CVE-2021-45046
published 2022-08-24CVE-2021-45046: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all…
PriorityP198critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-05-22
Exploited in the wild
EPSS
99.98%
100.0th percentile
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amazon | hotpatch | < 1.3.5 | 1.3.5 |
| apache | log4j | — | — |
| apache | log4j | >= 2.0.1 < 2.12.2 | 2.12.2 |
| apache | log4j | >= 2.13.0 < 2.16.0 | 2.16.0 |
| apache | logging | — | — |
| debian | apache-log4j2 | < apache-log4j2 2.16.0-1 (bookworm) | apache-log4j2 2.16.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kube-reporting | hive | — | — |
| paloalto | bridgecrew | — | — |
| paloalto | cortex_data_lake | — | — |
| paloalto | cortex_xdr_agent | — | — |
| paloalto | cortex_xpanse | — | — |
| paloalto | cortex_xsoar | — | — |
| paloalto | enterprise_data_loss_prevention | — | — |
| paloalto | exact_data_matching_cli | — | — |
| paloalto | expedition | — | — |
| paloalto | globalprotect_app | — | — |
| paloalto | iot_security | — | — |
| paloalto | okyo_garde | — | — |
| paloalto | pan-db_private_cloud | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect vulnerable log4j jar versions at or below 2.15 in running containers and container images using Qualys QID 376178 for CVE-2021-45046 ↗
- →Use the following QQL query in Qualys Container Security to identify containers and images impacted by CVE-2021-45046 (among other Log4Shell CVEs) ↗
- →Setting log4j2.noFormatMsgLookup to true does NOT mitigate CVE-2021-45046; detection/response should not rely on this flag as a bypass indicator ↗
- →CVE-2021-45046 was introduced in Log4j2 version 2.15.0; hunt for environments still running this specific version as they remain vulnerable ↗
- →Threat actors are observed using payloads incorporating key extraction attempts and base64 encoded payloads when exploiting CVE-2021-45046; hunt for base64-encoded JNDI strings in HTTP headers and log inputs ↗
- →Conti ransomware affiliates exploited CVE-2021-45046 (Log4Shell) on vulnerable VMware Horizon servers; monitor VMware Horizon for JNDI-based exploitation attempts and subsequent Cobalt Strike beaconing ↗
- →Post-exploitation indicators following CVE-2021-45046 exploitation include: Cobalt Strike beaconing, AnyDesk installation, IPC$ share access, RDP lateral movement, local admin account creation, and Windows Vault credential access ↗
- →Incomplete remediation of CVE-2021-45046 in OpenShift Metering hive containers (versions 4.6, 4.7, 4.8) was due to not all JndiLookup.class files being removed; verify removal of ALL JndiLookup.class instances from log4j-core jars as a detection/validation step ↗
- →Alternative lookup code paths exist beyond Thread Context attack vector; monitor for Logger.printf with user-controlled input and custom message factory usage as potential CVE-2021-45046 exploitation vectors ↗
- ·CVE-2021-45046 was re-scored from CVSS 3.7 to 9.0 after limited RCE was confirmed; initial assessments based on the lower score underestimate the risk ↗
- ·The formatMsgNoLookups=true setting (default in 2.15.0) does NOT fully mitigate CVE-2021-45046 due to alternative lookup paths; upgrading to a safe version or removing JndiLookup class is required ↗
- ·OpenShift Metering hive containers in versions 4.6, 4.7, and 4.8 may still be vulnerable even after applying the original Log4Shell patch, as not all JndiLookup.class files were removed ↗
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
ghsa10.0CRITICAL
osv10.0CRITICAL
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_cisco10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
vendor_apache9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
ghsa_unreviewed·2022-08-25·CVSS 10.0
CVE-2021-4125 [CRITICAL] CWE-502 GHSA-jr7q-cc2x-97vj: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all Jn
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
GHSA
GHSA-4vjw-ghvr-gv6w: Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
ghsa_unreviewed·2022-06-18·CVSS 10.0
CVE-2022-33915 [CRITICAL] CWE-362 GHSA-4vjw-ghvr-gv6w: Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1
Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates CVE-2021-44228 or CVE-2021-45046; it provides a temporary mitigation to CVE-2021-44228 by hotpatching the local Java virtual machines. To do so, it iterates through all running Java processes, performs several checks, and executes the Java virtual machine with the same permissions and capabilities as the running process to load the hotpatch. A local user could cause the hotpatch script to execute a binary with elevated privileges by running a custom java process that performs exec() of an SUID binary after the hotpatch has
GHSA
Security Advisory for "Log4Shell"
ghsa·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
Security Advisory for "Log4Shell"
osv·2022-01-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Security Advisory for "Log4Shell"
Security Advisory for "Log4Shell"
### Impact
A highly critical 0-day exploit (CVE-2021-44228) is found in Apache log4j 2 library on December 9, 2021.
This affects Apache log4j versions from 2.0-beta9 to 2.14.1 (inclusive).
This vulnerability allows a remote attacker to execute code on the server if the system logs an attacker-controlled string value with the attacker's JNDI LDAP server lookup.
Another vulnerability related to the same library, which was discovered on 12/14/2021 (CVE-2021-45046) and revealed another Remote Code Execution vulnerability, has been investigated by Hazelcast team as well and it is found that it does not affect Hazelcast Products under default configurations.
The finding of CVE-2021-45105 on 12/14/2021, which can cause a Denial of Service attack, was investi
OSV
CVE-2021-45046: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2
osv·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046: It was found that the fix to address CVE-2021-44228 in Apache Log4j 2
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
OSV
Incomplete fix for Apache Log4j vulnerability
osv·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] Incomplete fix for Apache Log4j vulnerability
Incomplete fix for Apache Log4j vulnerability
# Impact
The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack.
## Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apach
GHSA
Incomplete fix for Apache Log4j vulnerability
ghsa·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-502 Incomplete fix for Apache Log4j vulnerability
Incomplete fix for Apache Log4j vulnerability
# Impact
The fix to address [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in a remote code execution (RCE) attack.
## Affected packages
Only the `org.apache.logging.log4j:log4j-core` package is directly affected by this vulnerability. The `org.apache.logging.log4j:log4j-api` should be kept at the same version as the `org.apach
OSV
Remote code injection in Log4j
osv·2021-12-10
CVE-2021-44228 [CRITICAL] Remote code injection in Log4j
Remote code injection in Log4j
# Summary
Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser.
As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.16.0, this behavior has been disabled by default.
Log4j version 2.15.0 contained an earlier fix for the vulnerability, but that patch did not disable attacker-controlled JNDI lookups in all situations. For
GHSA
Remote code injection in Log4j
ghsa·2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 Remote code injection in Log4j
Remote code injection in Log4j
# Summary
Log4j versions prior to 2.16.0 are subject to a remote code execution vulnerability via the ldap JNDI parser.
As per [Apache's Log4j security guide](https://logging.apache.org/log4j/2.x/security.html): Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.16.0, this behavior has been disabled by default.
Log4j version 2.15.0 contained an earlier fix for the vulnerability, but that patch did not disable attacker-controlled JNDI lookups in all situations. For
VulnCheck
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
vulncheck·2021·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Affected: Apache Log4j2
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/cybersecurity-advisories/aa21-336a; https://cisa.gov/news-events/alerts/2021/12/22/mitigating-log4shell-and-other-log4j-related-vulnerabilities; https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet; https://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in
CISA
Apache Log4j2 Deserialization of Untrusted Data Vulnerability
cisa·2023-05-01·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Vulnerability: Apache Log4j2 Deserialization of Untrusted Data Vulnerability
Affected: Apache Log4j2
Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of CVE-2021-44228, where the Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Required Action: Apply updates per vendor instructions.
Notes: https://logging.apache.org/log4j/2.x/security.html; https://nvd.nist.gov/vuln/detail/CVE-2021-45046
Remediation Due Date: 2023-05-22
Red Hat
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
vendor_redhat·2021-12-16·CVSS 8.1
CVE-2021-4125 [HIGH] kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed.
Statement: This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6. The below previously shipped advisories were incomplete:
https://access.redhat.com/errata/RHSA-2021:5108
https://acc
Ubuntu
Apache Log4j 2 vulnerability
vendor_ubuntu·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Apache Log4j 2 vulnerability
Title: Apache Log4j 2 vulnerability
Summary: Apache Log4j 2 could be made to crash if it received specially crafted input.
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was
incomplete in certain non-default configurations. An attacker could use this
vulnerability to cause a denial of service.
Please see the following link for more information:
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Log4Shell
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
vendor_redhat·2021-12-14·CVSS 10.0
CVE-2021-45046 [CRITICAL] CWE-917 log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
log4j-core: DoS in log4j 2.x with thread context message pattern and context lookup pattern (incomplete fix for CVE-2021-44228)
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup pat
VMware
VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
vendor_vmware·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
VMSA-2021-0028: VMware Response to Apache Log4j Remote Code Execution Vulnerabilities (CVE-2021-44228, CVE-2021-45046)
Description Multiple products impacted by remote code execution vulnerabilities via Apache Log4j (CVE-2021-44228, CVE-2021-45046).
CVEs: CVE-2021-44228, CVE-2021-44832, CVE-2021-45046, CVE-2021-45105
Affected products: ESXi, NSX Data Center, NSX-T, VMware Aria, VMware Carbon Black, VMware Cloud Foundation, VMware HCX, VMware Horizon, VMware Identity Manager, VMware NSX, VMware SD-WAN, VMware Tanzu, VMware VeloCloud, VMware Workspace ONE, VMware vCenter Server, VMware vRealize, VMware vSphere
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-20 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library
On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed:
CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed:
CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
On December 18, 2021, a vulnerability in the Apache Log4j component affecting vers
Palo Alto
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
vendor_paloalto·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] CWE-94 Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Impact of Log4j Vulnerabilities CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832
Apache Log4j Java library is vulnerable to a remote code execution vulnerability CVE-2021-44228, known as Log4Shell, and related vulnerabilities CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. Log4Shell allows remote unauthenticated attackers with the ability to inject text into log messages to execute arbitrary code loaded from malicious servers with the privileges of the process utilizing Log4j.
These products and services are not affected by Log4Shell: Bridgecrew, Cortex Data Lake, Cortex XDR agents, Cortex XSOAR, Cortex Xpanse, Enterprise Data Loss Prevention (DLP), Expedition, the GlobalProtect app, IoT Security, Okyo Garde, PAN-DB Private Cloud, PAN-OS software running on firewall
Debian
CVE-2021-45046: apache-log4j2 - It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was i...
vendor_debian·2021·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046: apache-log4j2 - It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was i...
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.
Scope: local
bookworm: resolved (fixed in 2.16.0-1)
bullseye: resolved (fixed
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45105 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45105: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44228 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44228: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-44832 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-44832: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Cisco
Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
vendor_cisco·CVSS 3.1
CVE-2021-45046 Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
CVE-2021-45046: Vulnerabilities in Apache Log4j Library Affecting Cisco Products: December 2021
Critical Vulnerabilities in Apache Log4j Java Logging Library On December 9, 2021, the following critical vulnerability in the Apache Log4j Java logging library affecting all Log4j2 versions earlier than 2.15.0 was disclosed: CVE-2021-44228: Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints On December 14, 2021, the following critical vulnerability, which affects certain Apache Log4j use cases in versions 2.15.0 and earlier, was disclosed: CVE-2021-45046: Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack On December 18, 2021, a vulnerability in the Apache Log4j component affe
Apache
Apache logging: CVE-2021-45046
vendor_apache·CVSS 9.0
CVE-2021-45046 [CRITICAL] Apache logging: CVE-2021-45046
Apache logging: CVE-2021-45046
Summary Thread Context Lookup is vulnerable to remote code execution in certain configurations CVSS 3.x Score & Vector 9.0 CRITICAL (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) Components affected log4j-core Versions affected [2.0-beta9, 2.3.1) ∪ [2.4, 2.12.3) ∪ [2.13.0, 2.16.0) Versions fixed 2.3.1 (for Java 6), 2.12.3 (for Java 7), and 2.16.0 (for Java 8 and later)
Severity: critical
Affected versions: 2.3.1
No detection rules found.
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046-DAST
info:
name: Apache Log4j2 - Remote Code Injection
author: princechaddha
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Attackers can achieve remote code execution in non-default Log4j2 configurations through Thread Context Lookup Pattern manipulation, potentially compromising application servers.
remediation: |
Upgrade Apache Log4j2 to version 2.17.0 or later that completely removes support for Message Lookups and disables JNDI by default.
reference:
- https://securitylab.github.c
Nuclei
VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
VMware vRealize Operations is susceptible to a critical vulnerability in Apache Log4j which may allow remote code execution in an impacted vRealize Operations Tenant application.
Template:
id: vrealize-operations-log4j-rce
info:
name: VMware vRealize Operations Tenant - JNDI Remote Code Execution (Apache Log4j)
author: bughuntersurya
severity: critical
description: |
VMware vRealize Operations is susceptible to a critical vulnerability in Apache Log4j which may allow remote code execution in an impacted vRealize Operations Tenant application.
reference:
- https://www.vmware.com/security/advisories/VMSA-2021-0028.html
- https://core.vmware.com/vmsa-2021-0028-questions-answers-faq
- https://nvd.nist.gov/vuln/de
Nuclei
GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
nuclei·CVSS 10.0
CVE-2021-44228 [CRITICAL] GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
GoAnywhere Managed File Transfer is vulnerable to a remote command execution (RCE) issue via the included Apache Log4j.
Template:
id: goanywhere-mft-log4j-rce
info:
name: GoAnywhere Managed File Transfer - Remote Code Execution (Apache Log4j)
author: pussycat0x
severity: critical
description: GoAnywhere Managed File Transfer is vulnerable to a remote command execution (RCE) issue via the included Apache Log4j.
reference:
- https://www.goanywhere.com/cve-2021-44228-and-cve-2021-45046-goanywhere-mitigation-steps
- https://logging.apache.org/log4j/2.x/security.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cve-id: CVE-202
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046
info:
name: Apache Log4j2 - Remote Code Injection
author: ImNightmaree
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Log4j2.
reference:
- https://securitylab.github.com/advisories/GHSL-2021-1054_GHSL-2021-1055_log4j2/
- https://twitter.com/marcioalm/status/147174077158165
Metasploit
Log4Shell HTTP Scanner
metasploit·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell HTTP Scanner
Log4Shell HTTP Scanner
Versions of Apache Log4j2 impacted by CVE-2021-44228 which allow JNDI features used in configuration, log messages, and parameters, do not protect against attacker controlled LDAP and other JNDI related endpoints. This module will scan an HTTP end point for the Log4Shell vulnerability by injecting a format message that will trigger an LDAP connection to Metasploit. This module is a generic scanner and is only capable of identifying instances that are vulnerable via one of the pre-determined HTTP request injection points. These points include HTTP headers and the HTTP request path. Known impacted software includes Apache Struts 2, VMWare VCenter, Apache James, Apache Solr, Apache Druid, Apache JSPWiki, Apache OFBiz.
Qualys
Oracle Critical Patch Update, April 2026 Security Update Review
blogs_qualys·2026-04-22
CVE-2025-6965 Oracle Critical Patch Update, April 2026 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its second quarterly edition of this year’s Critical Patch Update. The update received patches for 481 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 139, constituting about 28% of the total patches released. Oracle Financial Services Applications and Oracle Fusion Middleware followed, with 75 and 59 security patches.
376 of the 481 security patches provided by the April Critical Patch Update (about 78%)
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Elastic
Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
blogs_elastic·2022-11-30·CVSS 10.0
CVE-2021-45046 [CRITICAL] Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
30 November 2022•Jake King
# Analysis of Log4Shell vulnerability & CVE-2021-45046
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.
4 min readDetection Engineering, Product Updates
> To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisoryhere.
>
>
>
>
> This document was updated on December 17, 2021 to reflect a revised CVSS score for CVE-2021-45046, and new findings by the community.
In recent days Log4Shell, or CVE-2021-44228, has dominated the news cycle in the world of information security and beyond. Elastic released an advisory detailing how Elastic products and users are impacted, and a blog post describing ho
Elastic
Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
blogs_elastic·2022-11-30·CVSS 10.0
CVE-2021-45046 [CRITICAL] Analysis of Log4Shell vulnerability & CVE-2021-45046 — Elastic Security Labs
## Analysis of Log4Shell vulnerability & CVE-2021-45046
In this post, we cover next steps the Elastic Security team is taking for users to continue to protect themselves against CVE-2021-44228, or Log4Shell.
To understand how Elastic is currently assessing internal risk of this vulnerability in our products please see the advisory here.
This document was updated on December 17, 2021 to reflect a revised CVSS score for CVE-2021-45046, and new findings by the community.
In recent days Log4Shell, or CVE-2021-44228, has dominated the news cycle in the world of information security and beyond. Elastic released an advisory detailing how Elastic products and users are impacted, and a blog post describing how our users can leverage Elastic Security to help defend their networks.
Many readers
Checkpoint
21st November– Threat Intelligence Report
blogs_checkpoint·2022-11-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] 21st November– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st November– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
US CISA has discovered nation-state threat activity affecting an American federal government entity. The attackers, who CISA estimates to be Iran-sponsored, exploited the 2021 ‘Log4Shell’ vulnerability in an unpatched server to gain initial access. Afterwards, the attackers deployed a cryptocurrency miner, harvested cred
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Tenable
log4shell Critical Vulnerability
blogs_tenable·2022-11-02·CVSS 10.0
CVE-2021-44228 [CRITICAL] log4shell Critical Vulnerability
by Cesar Navas November 2, 2022
On December 9, 2021, researchers published proof-of-concept (PoC) exploit code for a critical vulnerability in Apache Log4j, a Java logging library used by a number of applications and services. This vulnerability, identified as CVE-2021-44228, is a Remote Code Execution (RCE) vulnerability in Apache Log4j. This dashboard is designed to help organizations determine what assets may contain vulnerabilities susceptible to the Apache Log4j exploit.
The Log4j vulnerability impacts a number of services and applications used widely across the internet, and is actively being exploited with multiple proofs of concept on GitHub.
According to the published CVE, all Apache Log4j versions 2.14.1 or less are vulnerable. An unauthenticated remote attacker could exploit
Tenable
Defending Against Ransomware (ACT)
blogs_tenable·2022-11-01
Defending Against Ransomware (ACT)
by Josef Weiss November 1, 2022
Ransomware attacks leverage well-known and established software vulnerabilities and poor cyber hygiene. Successful ransomware attacks can cripple an organization with increased costs and lost revenue. This dashboard highlights a path forward with an in-depth focus on cyber hygiene by enabling IT staff to focus on vulnerabilities that could have the most impact to the organization in the event of a ransomware attack.
There are many contributing factors to the upward trend of ransomware. The most important is the large number of software vulnerabilities and misconfigurations, along with Active Directory (AD) weaknesses that enable attackers to escalate privileges. Threat actors leverage poor cyber hygiene to their advantage to gain a foothold and propagate a
Talos
Quarterly Report: Incident Response Trends in Q3 2022
blogs_talos·2022-10-25
Quarterly Report: Incident Response Trends in Q3 2022
### Ransomware and pre-ransomware engagements make up 40 percent of threats seen this quarter
For the first time since compiling these reports, Cisco Talos Incident Response saw an equal number of ransomware and pre-ransomware engagements, making up nearly 40 percent of threats this quarter.
It can be difficult to determine what constitutes a pre-ransomware attack if ransomware never executes and encryption does not take place. However, Talos IR assesses that the combination of Cobalt Strike and credential-harvesting tools like Mimikatz, paired with enumeration and discovery techniques, indicates a high likelihood that ransomware is the final objective.
This quarter featured a variety of publicly available tools and scripts hosted on GitHub repositories or other third-party websites to
Talos
Quarterly Report: Incident Response Trends in Q3 2022
blogs_talos·2022-10-25
Quarterly Report: Incident Response Trends in Q3 2022
## Quarterly Report: Incident Response Trends in Q3 2022
## Ransomware and pre-ransomware engagements make up 40 percent of threats seen this quarter
For the first time since compiling these reports, Cisco Talos Incident Response saw an equal number of ransomware and pre-ransomware engagements, making up nearly 40 percent of threats this quarter.
It can be difficult to determine what constitutes a pre-ransomware attack if ransomware never executes and encryption does not take place. However, Talos IR assesses that the combination of Cobalt Strike and credential-harvesting tools like Mimikatz, paired with enumeration and discovery techniques, indicates a high likelihood that ransomware is the final objective.
This quarter featured a variety of publicly available tools and scripts hosted
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
29th August – Threat Intelligence Report
blogs_checkpoint·2022-08-29
CVE-2021-44228 29th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 29th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 29th August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Montenegro has suffered a large-scale cyber attack, affecting multiple government services . According to some sources, it potentially affected critical infrastructure , transportation and telecommunications . Montenegro’s security agency has claimed that the attack was coordinated and persistent, and has concluded with cer
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Talos
Quarterly Report: Incident Response Trends in Q2 2022
blogs_talos·2022-07-26
Quarterly Report: Incident Response Trends in Q2 2022
For the first time in more than a year, ransomware was not the top threat Cisco Talos Incident Response (CTIR) responded to this quarter, as commodity malware surpassed ransomware by a narrow margin. This is likely due to several factors, including the closure of several ransomware groups, whether it be of their own volition or the actions of global law enforcement agencies and governments.
Commodity malware was the top observed threat this quarter, a notable development given the general decrease in observations of attacks leveraging commodity trojans in CTIR engagements since 2020. These developments coincide with a general resurgence of certain email-based trojans in recent months, as law enforcement and technology companies have continued to attempt to disrupt and affect email-based m
Talos
Quarterly Report: Incident Response Trends in Q2 2022
blogs_talos·2022-07-26
Quarterly Report: Incident Response Trends in Q2 2022
## Quarterly Report: Incident Response Trends in Q2 2022
For the first time in more than a year, ransomware was not the top threat Cisco Talos Incident Response (CTIR) responded to this quarter, as commodity malware surpassed ransomware by a narrow margin. This is likely due to several factors, including the closure of several ransomware groups, whether it be of their own volition or the actions of global law enforcement agencies and governments.
Commodity malware was the top observed threat this quarter, a notable development given the general decrease in observations of attacks leveraging commodity trojans in CTIR engagements since 2020 . These developments coincide with a general resurgence of certain email-based trojans in recent months, as law enforcement and technology companies ha
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
CVE-2017-5638 [CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Threat Research Center
Trend Reports
Vulnerabilities
## Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Unit 42
Published: July 21, 2022
Trend Reports
Vulnerabilities
Apache Log4j
CVE-2017-5638
CVE-2017-9841
CVE-2018-19986
CVE-2019-02320
CVE-2019-19597
CVE-2019-9082
CVE-2020-14882
CVE-2020-14883
CVE-2020-15505
CVE-2020-15506
CVE-2020-25078
CVE-2020-5902
CVE-2021-21315
CVE-2021-22986
CVE-2021-26855
CVE-2021-31805
CVE-2021-34473
CVE-2021-35464
CVE-2021-38647
CVE-2021-40438
CVE-2021-40539
CVE-2021-41773
CVE-2021-42013
CVE-2021-44228
CVE-2021-45046
CVE-2022-22963
CVE-2022-22965
Network security trends
Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are repo
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
[CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are reported every year, but not all are used by threat actors in real-world attacks. There are many reasons for this: a proof of concept (PoC) may not be available for attackers to weaponize, it may be too difficult to exploit the vulnerability, there may be a lack of accessible vulnerable software on the internet, or attackers may simply deem a vulnerability not worth exploiting due to low impact. Real-world defenders need real-world data on which vulnerabilities attackers are choosing to exploit – and where to focus protections.
In the 2022 Unit 42 Network Threat Trends Research Report, we’ve used data captured by the Palo Alto Networks Advanced Threat Prevention security service on Next-Generation Firewall and Prisma SASE from
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
## Avos ransomware group expands with new attack arsenal
By Flavio Costa ,
In a recent customer engagement, we observed a month-long AvosLocker campaign.
The attackers utilized several different tools, including Cobalt Strike , Sliver and multiple commercial network scanners.
The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell . While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
Talos
Avos ransomware group expands with new attack arsenal
blogs_talos·2022-06-21
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
- In a recent customer engagement, we observed a month-long AvosLocker campaign.
- The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
- The initial ingress point in this incident was a pair of VMWare Horizon Unified Access Gateways that were vulnerable to Log4Shell. While Cisco products were deployed on the network, the appliances were never configured, allowing the attacker to gain access to internal servers and maintain a foothold.
- During the time the attacker was active in the network, several security events were detected by the security products but were not reviewed by the security team, which could have prevented the ransomware activity.
## Threat Actor Profile: Avos
Avos is a ransomware gro
Unit42
Network Security Trends: November 2021 to January 2022
blogs_unit42·2022-05-31
Network Security Trends: November 2021 to January 2022
Threat Research Center
Threat Research
Vulnerabilities
## Network Security Trends: November 2021 to January 2022
Yue Guan
Published: May 31, 2022
Threat Research
Vulnerabilities
Apache Log4j
Attack analysis
Denial of service
Exploit in Wild
Network security trends
## Executive Summary
Unit 42 researchers continually observe network attacks and search for insights that can assist defenders. Here, we summarize key trends from November 2021 to January 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, for example, cross-site scripting or denial of service.
Cross-site scripting stood out as a commonly used t
Unit42
Network Security Trends: November 2021 to January 2022
blogs_unit42·2022-05-31·CVSS 9.8
[CRITICAL] Network Security Trends: November 2021 to January 2022
## Executive Summary
Unit 42 researchers continually observe network attacks and search for insights that can assist defenders. Here, we summarize key trends from November 2021 to January 2022. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity distribution. We also classify vulnerabilities to provide a clear view of the prevalence of, for example, cross-site scripting or denial of service.
Cross-site scripting stood out as a commonly used technique. Among around 6,443 newly published vulnerabilities, we found that a large portion (almost 10.6%) still involve this technique. However, by evaluating around 167 million attack sessions and focusing on the latest exploits in the wild, we conclude that remote code execution
Talos
Quarterly Report: Incident Response trends in Q1 2022
blogs_talos·2022-04-26
Quarterly Report: Incident Response trends in Q1 2022
### Ransomware continues as the top threat, while a novel increase in APT activity emerges
Ransomware was still the top threat Cisco Talos Incident Response (CTIR) saw in active engagements this quarter, continuing a trend that started in 2020. As mentioned in the 2021 year-in-review report, CTIR continues to deal with an expanding set of ransomware adversaries and major cybersecurity incidents affecting organizations worldwide.
The first quarter of 2022 also featured an increase in engagements involving advanced persistent threat (APT) activity. This included Iranian state-sponsored MuddyWater APT activity, China-based Mustang Panda activity leveraging USB drives to deliver the PlugX remote access trojan (RAT), and a suspected Chinese adversary dubbed “Deep Panda” exploiting Log4j.
##
Talos
Quarterly Report: Incident Response trends in Q1 2022
blogs_talos·2022-04-26
Quarterly Report: Incident Response trends in Q1 2022
## Quarterly Report: Incident Response trends in Q1 2022
## Ransomware continues as the top threat, while a novel increase in APT activity emerges
Ransomware was still the top threat Cisco Talos Incident Response (CTIR) saw in active engagements this quarter, continuing a trend that started in 2020. As mentioned in the 2021 year-in-review report , CTIR continues to deal with an expanding set of ransomware adversaries and major cybersecurity incidents affecting organizations worldwide.
The first quarter of 2022 also featured an increase in engagements involving advanced persistent threat (APT) activity. This included Iranian state-sponsored MuddyWater APT activity , China-based Mustang Panda activity leveraging USB drives to deliver the PlugX remote access trojan (RAT), and a suspected C
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
# How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana
2022/01/27
Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021. So I’m back to write about how to detect the infamous Log4j vulnerability (CVE-2021-44228) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Stages of Log4j attack
Before diving straight into detection/prevention, let’s first take a look at the di
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Network
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana 2022/01/27 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent f
Trendmicro
How to Detect Apache Log4j Vulnerabilities
blogs_trendmicro·2022-01-27·CVSS 10.0
[CRITICAL] How to Detect Apache Log4j Vulnerabilities
Red
## How to detect Apache Log4j vulnerabilities
Explore how to detect Apache Log4j (Log4Shell) vulnerabilities using cloud-native security tools.
By: Nitesh Surana Jan 27, 2022 Read time: ( words)
Save to Folio
In my previous blog, I reviewed how to detect Apache HTTP server exploitation from vulnerabilities in October. Weirdly enough, I wrote that article before the Apache Log4j (Log4Shell) news broke in December 2021 . So I’m back to write about how to detect the infamous Log4j vulnerability ( CVE-2021-44228 ) that allows attackers to achieve remote code execution on the victim servers using the vulnerable versions of the popular library in exposed web applications/services.
Source: Trend Micro
The above depicts a vulnerable public facing web service that logs the User-Agent fie
Tenable
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
blogs_tenable·2022-01-19
Oracle January 2022 Critical Patch Update Addresses 266 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
blogs_huntress·2022-01-15
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
On January 5, the UK’s National Health Service (NHS) alerted that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via web shells. These web shells allow unauthenticated attackers to remotely execute commands on your server as NT AUTHORITY\SYSTEM (root privileges). According to Shodan, ~25,000 Horizon servers are currently internet accessible worldwide.
Our team is continuing to track this activity and this post will be updated with new information as it becomes available.
Image Source: NHS - https://digital.nhs.uk/cyber-alerts/2022/cc-4002
Based on Huntress’ dataset of 180 Horizon servers, we’ve validated NHS’ intel and discovered 10% of these systems (18) had been backdoored with a modified absg-worker.js w
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
CVE-2021-45046 (critical)
CVE-2021-4104 (high)
CVE-2021-42550 (moderate)
CVE-2021-45105 (moderate)
CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software can b
Sentinelone
Log4j One Month On | Crimeware and Exploitation Roundup
blogs_sentinelone·2022-01-10·CVSS 7.5
CVE-2021-44228 [HIGH] Log4j One Month On | Crimeware and Exploitation Roundup
It has been 31 days since the initial public disclosure of a critical remote code execution (RCE) vulnerability in the Apache Log4j logging library that upended enterprise security at the close of 2021. In that time, since the initial CVE-2021-44228 (critical), we’ve already seen five more related CVEs
- CVE-2021-45046 (critical)
- CVE-2021-4104 (high)
- CVE-2021-42550 (moderate)
- CVE-2021-45105 (moderate)
- CVE-2021-44832 (moderate))
and several updates to the library from 2.15.01 on December 9th to 2.17.1 on December 28th.
The importance of this class of vulnerabilities in such a ubiquitous library must not be forgotten with the next spin of the cyber news cycle: with millions of vulnerable devices, attacks are likely to continue for as long as such devices running unpatched software
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
QID 376157/ CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
QID 376178/ CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
QID 376194/ CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptible
Qualys
How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
blogs_qualys·2021-12-27·CVSS 10.0
CVE-2021-44228 [CRITICAL] How to Discover Log4Shell Vulnerabilities in Running Containers & Images | Qualys
If you run Java applications in containers, then it is critical that you check for Log4Shell vulnerabilities, given the high severity of this potential exploit. Qualys Container Security offers multiple methods to help you detect Log4Shell in your container environment. The Container Security sensor checks both running containers and container images for the following vulnerabilities:
- QID 376157/CVE-2021-44228 – Detect venerable log4 jar for versions at or below 2.14
- QID 376178/CVE-2021-45046 – Detect venerable log4 jar for versions at or below 2.15
- QID 376194/CVE-2021-45105 – Detect venerable log4 jar for versions at or below 2.16
Qualys highly recommends running a vulnerability scan against all your running containers because Java applications running the container are susceptibl
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek 2021/12/23 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Sfruttamento vulnerabilità
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits y vulnerabilidades
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many ot
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
# Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek
2021/12/23
Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many other
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Exploits & Vulnerabilities
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many oth
Trendmicro
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
blogs_trendmicro·2021-12-23
Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
Ausnutzung von Schwachstellen
## Examining Log4j Vulnerabilities in Connected Cars and Charging Stations
In this entry we look into how Log4j vulnerabilities affect devices or properties embedded in or used for connected cars, specifically chargers, in-vehicle infotainment systems, and digital remotes for opening cars.
By: Sébastien Dudek Dec 23, 2021 Read time: ( words)
Save to Folio
Since its disclosure on Dec. 9, a vast number of articles have been written on the remote code execution (RCE) vulnerability in the library Apache Log4j — a reflection of its impact. The library is used by innumerable programs to easily release log statements without modifying the code. This means that it has an expansive attack surface, with Amazon, Apple, Cloudflare, Google, Tencent, Twitter, and many
Tenable
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
blogs_tenable·2021-12-21
Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
blogs_fortinet·2021-12-21·CVSS 10.0
CVE-2021-44228 [CRITICAL] Critical Apache Log4j Vulnerability Updates | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Critical Apache Log4j Vulnerability Updates
By Shunichi Imano, James Slaughter, and Geri Revay | December 21, 2021
Beginning December 9th, most of the internet-connected world was forced to reckon with a critical new vulnerability discovered in the Apache Log4j framework deployed in countless servers. Officially labeled CVE-2021-44228, but colloquially known as “Log4Shell”, this vulnerability is both trivial to exploit and allows for full remote code execution on a target system. This has earned the vulnerability a CVSS score of 10 – the maximum.
On December 14th, the Apache Software Foundation revealed a second Log4j vulnerability (CVE-2021-45046). It was initially identified as a Denial-of-Service (DoS) vulnerability with a CVSS score of 3.7 and modera
Qualys
6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment
blogs_qualys·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] 6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment
## Table of Contents
How the Exploit Works
Key Points
Prevent Future Attacks
Free 30 Days of Qualys Multi-Vector EDR
In recent days, the cybersecurity industry has been rapidly assessing the full impact of the Log4Shell (CVE-2021-44228 and CVE-2021-45046) vulnerability. Many organizations are quickly trying to figure out whether this vulnerability is within their environment, and where. The next question a security operations team will ask is if its presence has been exploited. This is critical to answer quickly given Log4Shell’s high severity, the pervasiveness of Java, and its ease of exploitation.
## Free Trial
## Get 30 Days of Qualys Multi-Vector EDR Free
In a previous blog we discussed how to mitigate the threat of this vulnerability via a patch or configuration change. Now l
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
Important notice
A summary of the Log4Shell situation
The Log4Shell vulnerability webinar FAQ
Authors
Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in millions of commer
Securelist
Answering Log4Shell-related questions
blogs_securelist·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] Answering Log4Shell-related questions
Table of Contents
- Important notice
- A summary of the Log4Shell situation
- The Log4Shell vulnerability webinar FAQ
Authors
- Kaspersky
## Important notice
On December 18th, Log4j version 2.17.0 was released to address open vulnerabilities. It is highly recommended to update your systems as soon as possible.
History of the Log4j library vulnerabilities
- CVE-2021-44228 (initial vulnerability) – partially fixed in 2.15.0
- CVE-2021-45046 (present in Log4j 2.15.0) – fixed in 2.16.0
- CVE-2021-45105 (present in Log4j 2.16.0) – fixed in 2.17.0
## A summary of the Log4Shell situation
On December 9th, a Chinese researcher posted his now-monumental discovery on Twitter: there was a Remote Code Execution vulnerability in the popular Apache Log4j library. This library is used in million
Qualys
New Options Profiles for Log4Shell Detection | Qualys
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection | Qualys
#### Table of Contents
- Importing Option Profiles
- Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
1. Log4Shell – Authenticated Scan
2. Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library.
Choose from the Log4Shell – Authenticated Scan or Log4Shell –
Qualys
6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment | Qualys
blogs_qualys·2021-12-20·CVSS 10.0
CVE-2021-44228 [CRITICAL] 6 Ways to Quickly Detect a Log4Shell Exploit in Your Environment | Qualys
#### Table of Contents
- How the Exploit Works
- Key Points
- Prevent Future Attacks
- Free 30 Days of Qualys Multi-Vector EDR
In recent days, the cybersecurity industry has been rapidly assessing the full impact of the Log4Shell (CVE-2021-44228 and CVE-2021-45046) vulnerability. Many organizations are quickly trying to figure out whether this vulnerability is within their environment, and where. The next question a security operations team will ask is if its presence has been exploited. This is critical to answer quickly given Log4Shell’s high severity, the pervasiveness of Java, and its ease of exploitation.
#### Free Trial
### Get 30 Days of Qualys Multi-Vector EDR Free
Get the Free Trial
In a previous blog we discussed how to mitigate the threat of this vulnerability via a patch
Qualys
New Options Profiles for Log4Shell Detection
blogs_qualys·2021-12-20
New Options Profiles for Log4Shell Detection
## Table of Contents
Importing Option Profiles
Search Lists
We have now added two new option profiles to our library for Log4Shell vulnerabilities. Option profiles define the settings you want to use for your scan. These new option profiles are tuned to quickly detect the Log4Shell vulnerability on assets in your environment.
The following two pre-configured option profiles are now available in the library to help you get started:
Log4Shell – Authenticated Scan
Log4Shell – Unauthenticated Scan
You can import these profiles into your account and use them as-is or edit them as needed.
## Importing Option Profiles
To import our option profiles, go to Scans > Option Profiles > New and select Import from Library .
Choose from the Log4Shell – Authenticated Scan or Log4Shell – Unauthent
Tenable
CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
blogs_tenable·2021-12-17·CVSS 7.5
[HIGH] CVE-2021-44228, CVE-2021-45046, CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Qualys
Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Log4Shell Log4j Vulnerability Test | CVE-2021-45046 Detection | Qualys
#### Table of Contents
- About CVE-2021-44228
- Detecting the Vulnerability with Qualys WAS
- WAS Log4Shell Detection Methodology with Qualys Periscope
- Scan Configurations :
- About CVE-2021-45046
- About CVE-2021-44832
- Solution
- Credits
- References:
- Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
#### Free Trial
### Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Get the Free Trial
Successful exploitation of this vulnerability could allow a remote attacker
Qualys
Is Your Web Application Exploitable By Log4Shell Vulnerability?
blogs_qualys·2021-12-15·CVSS 10.0
CVE-2021-44228 [CRITICAL] Is Your Web Application Exploitable By Log4Shell Vulnerability?
## Table of Contents
About CVE-2021-44228
Detecting the Vulnerability with Qualys WAS
WAS Log4Shell Detection Methodology with Qualys Periscope
Scan Configurations :
About CVE-2021-45046
About CVE-2021-44832
Solution
Credits
References:
Contributors
On December 09, 2021, a critical remote code execution vulnerability was identified in Apache Log4j2 after proof-of-concepts were leaked publicly, affecting Apache Log4j 2.x <= 2.15.0-rc1. The vulnerability is being tracked as CVE-2021-44228 with CVSSv3 10 score and affects numerous applications which are using the Log4j2 library.
## Free Trial
## Quickly Identify Your Vulnerable Web Applications Using Our Cloud Platform
Successful exploitation of this vulnerability could allow a remote attacker to download and execute arbitrary c
Zscaler
Mitigate Log4Shell and Remote Code Execution Risk with Deception | Zscaler
blogs_zscaler·2021-12-15·CVSS 9.0
[CRITICAL] Mitigate Log4Shell and Remote Code Execution Risk with Deception | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Log4Shell: 5 Steps The OT Community Should Take Right Now
blogs_tenable·2021-12-14
Log4Shell: 5 Steps The OT Community Should Take Right Now
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits y vulnerabilidades
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang 2021/12/13 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a
Securelist
CVE-2021-44228 vulnerability in Apache Log4j library
blogs_securelist·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228 vulnerability in Apache Log4j library
Table of Contents
CVE-2021-44228 and CVE-2021-45046 summary
CVE-2021-44228 and CVE-2021-45046 technical details
CVE-2021-44228 exploitation statistics
Mitigations for CVE-2021-44228 and CVE-2021-45046
Affected Kaspersky products
Indicators of compromise (IOC)
Authors
AMR
Updated 2021-12-20
## CVE-2021-44228 and CVE-2021-45046 summary
A couple of weeks ago information security media reported the discovery of the critical vulnerability CVE-2021-44228 in the Apache Log4j library (CVSS severity level 10 out of 10). The threat, also named Log4Shell or LogJam , is a Remote Code Execution (RCE) class vulnerability. If an attacker manages to exploit it on a vulnerable server, they gain the ability to execute arbitrary code and potentially take full control of the system. A publicly publ
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Sfruttamento vulnerabilità
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Securelist
CVE-2021-44228 vulnerability in Apache Log4j library
blogs_securelist·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228 vulnerability in Apache Log4j library
Table of Contents
- CVE-2021-44228 and CVE-2021-45046 summary
- CVE-2021-44228 and CVE-2021-45046 technical details
- CVE-2021-44228 exploitation statistics
- Mitigations for CVE-2021-44228 and CVE-2021-45046
- Affected Kaspersky products
- Indicators of compromise (IOC)
Authors
- AMR
Updated 2021-12-20
## CVE-2021-44228 and CVE-2021-45046 summary
A couple of weeks ago information security media reported the discovery of the critical vulnerability CVE-2021-44228 in the Apache Log4j library (CVSS severity level 10 out of 10). The threat, also named Log4Shell or LogJam, is a Remote Code Execution (RCE) class vulnerability. If an attacker manages to exploit it on a vulnerable server, they gain the ability to execute arbitrary code and potentially take full control of the system. A publ
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
## Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang Dec 13, 2021 Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release .
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published
Tenable
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
blogs_tenable·2021-12-13
Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
blogs_trendmicro·2021-12-13·CVSS 10.0
CVE-2021-44228 [CRITICAL] Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Exploits & Vulnerabilities
# Patch Now: Apache Log4j Vulnerability Called Log4Shell Actively Exploited
Log4Shell, also known as CVE-2021-44228, was first reported privately to Apache on November 24 and was patched on December 9. It affects Apache Struts, Apache Solr, Apache Druid, Elasticsearch, Apache Dubbo, and VMware vCenter.
By: Ranga Duraisamy, Ashish Verma, Miguel Carlo Ang
2021/12/13
Read time: ( words)
Save to Folio
Update as of Dec 28, 2021: The latest Log4j vulnerability, CVE-2021-44832, has now been addressed in the Log4j 2.17.1 release.
Update as of Dec 22, 2021: The Impact section has been updated with information on the various payloads discovered after the start of the Log4Shell attacks.
Update as of Dec. 19, 2021: Our researchers at Zero Day Initiative published a g
Tenable
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
blogs_tenable·2021-12-12
Apache Log4j Flaw Puts Third-Party Software in the Spotlight
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Microsoft
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
blogs_microsoft·2021-12-12·CVSS 10.0
CVE-2021-44228 [CRITICAL] Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability
Research
December 11, 2021
Devices with Log4j vulnerability alerts and additional other alert-related context
This query surfaces devices with Log4j-related alerts and adds additional context from other alerts on the device.
// Get any devices with Log4J related Alert Activity
let DevicesLog4JAlerts = AlertInfo
| where Title in~('Suspicious script launched',
'Exploitation attempt against Log4j (CVE-2021-44228)',
'Suspicious process executed by a network service',
'Possible target of Log4j exploitation (CVE-2021-44228)',
'Possible target of Log4j exploitation',
'Possible Log4j exploitation',
'Network connection seen in CVE-2021-44228 exploitation',
'Log4j exploitation detected',
'Possible exploitation of CVE-2021-44228',
'Possible target of Log4j vulnerability (CVE-2021-44228) scanning'
Fortinet
Apache Log4j Vulnerability | Fortinet Blog
blogs_fortinet·2021-12-12
Apache Log4j Vulnerability | Fortinet Blog
PSIRT BLOGS
Apache Log4j Vulnerability
By Carl Windsor | December 12, 2021
Apache Log4j Vulnerability Defined
Apache Log4j is a Java-based logging audit framework and Apache Log4j2 1.14.1 and below are susceptible to a remote code execution vulnerability where an attacker can leverage this vulnerability to take full control of a machine.
This module is a prerequisite for other software which means it can be found in many products and is trivial to exploit. It is critical that organizations take immediate action to inventory their systems and prioritize remediation.
Impacted Versions
Apache Log4j 2.x <= 2.15.0-rc1
CVSS: 10 (CRITICAL)
Apache Log4j Vulnerability Overview
Until a few days ago, most people would not have had any knowledge of the Log4j2 software. However, this little-know
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
- A new critical remote code execution vulnerability in Apache Log4j2, a Java-based logging tool, is being tracked as CVE-2021-44228.
- Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here.
- Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
- Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
- Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
- Due to the ease and rate of exploitation
Sentinelone
CVE-2021-44228: Apache Log4j Vulnerability
blogs_sentinelone·2021-12-11·CVSS 10.0
CVE-2021-44228 [CRITICAL] CVE-2021-44228: Apache Log4j Vulnerability
## Executive Summary
A new critical remote code execution vulnerability in Apache Log4j2 , a Java-based logging tool, is being tracked as CVE-2021-44228.
Further vulnerabilities in the Log4j library, including CVE-2021-44832 and CVE-2021-45046, have since come to light, as detailed here .
Major services and applications globally are impacted by these vulnerabilities due to the prevalence of Log4j2’s use in many web apps.
Exploit proof-of-concept code is widely available and internet-wide scanning suggests active exploitation.
Exploit attempts have led to commodity cryptominer, ransomware and other payloads. SentinelOne expects further opportunistic abuse by a wide variety of attackers, including further ransomware and nation-state actors.
Due to the ease and rate of exploitation atte
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
DateDescription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Additional IOCs.
Dec. 13, 2021
Added additional vulnerability informatio
Tenable
CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
blogs_tenable·2021-12-10·CVSS 10.0
[CRITICAL] CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Management (CSPM)
Compliance
Cyber insurance
Data Security Posture Management (DSPM)
Google Cloud security
Infrastructure as Code (IaC) security
Kubernetes Security Pos
Talos
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
blogs_talos·2021-12-10·CVSS 10.0
[CRITICAL] Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
## Update History
Dec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021
Added additional vulnerability and mitigation information; added section on guidance for developers; timeline.
Dec. 16, 2021
Added additional vulnerability and mitigation information; added event timeline; relevant advisory information.
Dec. 15, 2021
Added observations on exploitation activity; updated coverage information. Additional IOCs.
Dec. 14, 2021
Added new CVE details; updated coverage information; additional mitigation guidance; additional threat vectors; Ad
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 10.0
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, depending on how the system is configured, an attacker is able to instruct that system to download and subsequently execute a malicious payload. Due to the discovery of this exploit being so recent, there are still many servers, both on-premises and within cloud environments, that have yet to be patched. Like many high severity RCE exploits, thus far, massive scanning activity for CVE-2021-44228 has begun on the internet with the intent of seeking o
Unit42
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
blogs_unit42·2021-12-10·CVSS 9.8
CVE-2021-44228 [CRITICAL] Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Threat Research Center
Threat Research
Vulnerabilities
## Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228) (Updated)
Tao Yan
Qi Deng
Haozhe Zhang
Yu Fu
Josh Grunzweig
Mike Harbison
Robert Falcone
Published: December 10, 2021
Threat Research
Vulnerabilities
Apache Log4j
CVE-2017-5645
CVE-2019-17571
CVE-2021-44228
CVE-2021-44832
CVE-2021-45046
CVE-2021-45105
Denial of service
Exploit
Log4j
Log4j 2
RCE
## Executive Summary
On Dec. 9, 2021, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified being exploited in the wild. Public proof of concept (PoC) code was released and subsequent investigation revealed that exploitation was incredibly easy to perform. By submitting a specially crafted request to a vu
Greynoiseio
NoiseLetter
blogs_greynoiseio
NoiseLetter
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
## Topic
## Detection Engineering
## 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
## The Engineer's Guide to Elastic Detections as Code
This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.
## Investigating a Mysteriously Malformed Authenticode Signature
An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.
## Taking SHELLTE
Trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
blogs_trendmicro
Cos'è la vulnerability Apache Log4J (Log4Shell)?
Collega la protezione dalle minacce e la gestione del rischio informatico
Scopri le soluzioni dei partner approvate da Trend per la nostra piattaforma leader
Il leader nella gestione dell'esposizione: trasformare la visibilità del rischio informatico in una sicurezza decisiva e proattiva
Blocca gli aggressori con una visibilità ineguagliabile, basata sull'intelligenza di XDR, Agentic SIEM e Agentic SOAR, che non lascia agli aggressori alcun posto dove nascondersi.
La piattaforma di sicurezza cloud più affidabile per sviluppatori, team di sicurezza e aziende
Estensione della visibilità al cloud e semplificazione delle indagini SOC
Semplifica la sicurezza delle applicazioni native per il cloud con scansione avanzata delle immagini dei container, controllo dell'accesso basato su criteri
Greynoiseio
GreyNoise Round Up: Product Updates
blogs_greynoiseio
GreyNoise Round Up: Product Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
blogs_trendmicro
Was ist die Apache Log4j/Log4Shell vulnerability?
Verbindet den Schutz vor Bedrohungen und das Management des Cyberrisikos
Spitzenreiter im Bereich Exposure Management – macht Cyberrisiken transparent und sorgt für entschlossene, proaktive Sicherheit
Stoppen Sie Angreifer mit unübertroffener Transparenz, unterstützt durch XDR, agentenbasiertes SIEM und SOAR – damit Angreifer sich nirgendwo mehr verstecken können
Nutzen Sie die bewährte Cloud-Sicherheitsplattform für Entwickler, Sicherheitsteams und Unternehmen.
Erweiterung der Transparenz auf die Cloud und Optimierung von SOC-Untersuchungen
Vereinfachen Sie die Sicherheit für Ihre Cloud-nativen Anwendungen durch erweitertes Container-Image-Scanning, richtlinienbasierte Zugriffssteuerung und Container-Laufzeitschutz.
Schützen Sie Anwendungsworkflows und Cloud-Speicher vor neuen und k
Crowdstrike
How CrowdStrike Protects Customers from Log4Shell Threats
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How CrowdStrike Protects Customers from Log4Shell Threats
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
blogs_huntress
VMware Horizon Servers Actively Being Hit With Cobalt Strike | Huntress
On January 5, the UK’s National Health Service (NHS) alerted that hackers were actively targeting Log4Shell vulnerabilities in VMware Horizon servers in an effort to establish persistent access via web shells. These web shells allow unauthenticated attackers to remotely execute commands on your server as NT AUTHORITY\SYSTEM (root privileges). According to Shodan, ~25,000 Horizon servers are currently internet accessible worldwide.
Our team is continuing to track this activity and this post will be updated with new information as it becomes available.
Image Source: NHS - https://digital.nhs.uk/cyber-alerts/2022/cc-4002
Based on Huntress’ dataset of 180 Horizon servers, we’ve validated NHS’ intel and discovered 10% of these systems (18) had been backdoored with a modified absg-worker.js w
Trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
blogs_trendmicro
¿Qué es la vulnerabilidad de Apache Log4J (Log4Shell)?
Elimine la separación entre la protección frente a amenazas y la gestión del riesgo cibernético
El líder en gestión de exposiciones: convirtiendo la visibilidad de los ciberriesgos en una seguridad proactiva y decisiva
Detenga a los adversarios con una visibilidad sin igual, impulsada por la inteligencia de XDR, SIEM agente y SOAR agente para dejar a los atacantes en ningún lugar
La plataforma de seguridad en la nube más fiable para desarrolladores, equipos de seguridad y empresas
Amplíe la visibilidad de la nube y optimice las investigaciones del SOC
Simplifique la seguridad de sus aplicaciones nativas en la nube con un avanzado análisis de imágenes de contenedor, control de admisión con base en política y protección de tiempo de ejecución del contenedor
Proteja el flujo de trabajo
Huntress
CVE-2021-45046 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 10.0
CVE-2021-45046 [CRITICAL] CVE-2021-45046 Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2021-45046 Vulnerability
Published: 2/20/2025
Written by: Lizzie Danielson
## What is CVE-2021-45046 vulnerability?
CVE-2021-45046 is a Remote Code Execution (RCE) vulnerability connected to the widely-used Apache Log4j logging library, which allows attackers to manipulate logging data. Initially perceived as a denial-of-service risk, it was later revealed to enable attackers to execute arbitrary code in certain non-default configurations, making it highly critical.
## When was it discovered?
CVE-2021-45046 was disclosed on December 14, 2021, following the initial CVE-2021-44228 ("Log4Shell") vulnerability. The flaw was identified during the response to the first issue, with contributions from Apache maintainers and security researchers.
## Affected products & versions
Product
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
#### Topic
# Detection Engineering
Subscribe
#### 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
4 February 2026The Engineer's Guide to Elastic Detections as CodeThis post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.4 September 2025Investigating a Mysteriously Malformed Authenticode SignatureAn in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented ke
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Crowdstrike
How CrowdStrike Protects Customers from Log4Shell Threats
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How CrowdStrike Protects Customers from Log4Shell Threats
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Greynoiseio
Malicious Tag Roundup (January 2022)
blogs_greynoiseio
Malicious Tag Roundup (January 2022)
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
blogs_trendmicro
What Is Apache Log4J (Log4Shell) Vulnerability?
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data centre, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Crowdstrike
December 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] December 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Greynoiseio
Log4j Analysis: What to Do
blogs_greynoiseio·CVSS 10.0
[CRITICAL] Log4j Analysis: What to Do
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Greynoiseio
KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
blogs_greynoiseio·CVSS 9.0
[CRITICAL] KEV'd: CVE-2021-45046, CVE-2023-21839, and CVE-2023-1389
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
arXiv
The Road of Adaptive AI for Precision in Cybersecurity
arxiv_fulltext·2025-12-05
The Road of Adaptive AI for Precision in Cybersecurity
## Abstract
Cybersecurity's evolving complexity presents unique challenges and opportunities for AI research and practice. This paper shares key lessons and insights from designing, building, and operating production-grade GenAI pipelines in cybersecurity, with a focus on the continual adaptation required to keep pace with ever-shifting knowledge bases, tooling, and threats.
Our goal is to provide an actionable perspective for AI practitioners and industry stakeholders navigating the frontier of GenAI for cybersecurity, with particular attention to how different adaptation mechanisms complement each other in end-to-end systems.
We present practical guidance derived from real-world deployments, propose best practices for leveraging retrieval- and model-level adaptation, and highlight ope
arXiv
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
arxiv_fulltext·2024-02-15
Hacktivism Goes Orbital: Investigating NB65's Breach of ROSCOSMOS
## Abstract
In March of 2022, Network battalion 65 (NB65), a hacktivist affiliate of Anonymous, publicly asserted its successful breach of ROSCOSMOS's satellite imaging capabilities in response to Russia's invasion of Ukraine. NB65 disseminated a series of primary sources as substantiation, proclaiming the incapacitation of ROSCOSMOS's space-based vehicle monitoring system and doxing of related proprietary documentation. Despite the profound implications of hacktivist incursions into the space sector, the event has garnered limited attention due to the obscurity of technical attack vectors and ROCOSMOS's denial of NB65's allegations. Through analysis of NB65's released primary sources of evidence, this paper uncovers the probable vulnerabilities and exploits that enabled the alleged breac
arXiv
Attack Techniques and Threat Identification for Vulnerabilities
arxiv_fulltext·2022-06-22
Attack Techniques and Threat Identification for Vulnerabilities
Attack Techniques and Threat Identification for Vulnerabilities
Constantin Adam
Muhammed Fatih Bulut
Daby Sow
cmadam, mfbulut, [email protected]
IBM T.J. Watson Research Center
Yorktown Heights
NY
USA
Steven Ocepek
Chris Bedell
steve.ocepek, [email protected]
IBM Security X-Force Red
USA
Lilian Ngweta
[email protected]
Rensselaer Polytechnic Institute
Troy
NY
USA
Adam and Bulut, et al.
## Abstract
Modern organizations struggle with what is often considered an insurmountable number of vulnerabilities that are discovered and reported by their network and application vulnerability scanners. Therefore, prioritization and focus become critical, to spend their limited time on the highest risk vulnerabilities. In doing this, it is important for these organizations not only to
arXiv
The Race to the Vulnerable: Measuring the Log4j Shell Incident
arxiv_fulltext·2022-06-07
The Race to the Vulnerable: Measuring the Log4j Shell Incident
IEEEexample:BSTcontrolNew
5pt
textblock0.8(0.1,0.02)
If you cite this paper, please use the TMA reference:
R. Hiesgen, M. Nawrocki, T. C. Schmidt, and M. Wählisch.
2022. The Race to the Vulnerable: Measuring the Log4j Shell Incident.
In Proc. of Network Traffic Measurement and Analysis Conference (TMA ’22).
IFIP, 9 pages.
textblock
The Race to the Vulnerable:
Measuring the Log4j Shell Incident
Raphael Hiesgen
HAW Hamburg\ [email protected]
Marcin Nawrocki
Freie Universit\"at Berlin\ [email protected]
Thomas C. Schmidt
HAW Hamburg\ [email protected]
Matthias W\"ahlisch
Freie Universit\"at Berlin\ [email protected]
## Abstract
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It
https://access.redhat.com/security/cve/CVE-2021-4125https://access.redhat.com/security/cve/CVE-2021-44228https://access.redhat.com/security/cve/CVE-2021-45046https://bugzilla.redhat.com/show_bug.cgi?id=2033121https://github.com/kube-reporting/hive/pull/71https://github.com/kube-reporting/hive/pull/72https://github.com/kube-reporting/hive/pull/73https://access.redhat.com/security/cve/CVE-2021-4125https://access.redhat.com/security/cve/CVE-2021-44228https://access.redhat.com/security/cve/CVE-2021-45046https://bugzilla.redhat.com/show_bug.cgi?id=2033121https://github.com/kube-reporting/hive/pull/71https://github.com/kube-reporting/hive/pull/72https://github.com/kube-reporting/hive/pull/73
2022-08-24
Published
2023-05-01
Added to CISA KEV
Exploited in the wild