- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
Disclaimer: This threat is rapidly evolving by the hour. Unit 42 researchers are updating this Unit 42 blog in real time, and therefore the blog serves as our single source of truth. The information provided is for general informational purposes only.
On December 9, a remote code execution (RCE) vulnerability in Apache Log4j 2 was identified as being exploited in the wild. Apache Log4j is an open-source logging utility that is leveraged within numerous Java applications around the world. The release of public proof-of-concept (PoC) code and subsequent investigation revealed that the exploitation was incredibly easy to perform. By submitting a specially crafted request to a vulnerable system, the attacker can instruct the system to download and subsequently execute a malicious payload. Due to its recent discovery, there are still many on-premises and cloud servers that have yet to be patched.
The exploit code for the CVE-2021-44228 vulnerability has been made publicly available, and massive scanning activity has begun on the internet with the intent of seeking out and exploiting unpatched systems. The Unit 42 Threat Intelligence and product development teams continue to monitor this situation for additional details and updates and will share the latest information on the exploit and how to defend against it.
Register now for a webinar with Jen Miller-Osborn, deputy director for the Unit 42 threat research team, to learn:
For the most up-to-date information on theApache Log4j vulnerability, please visit the Unit 42 blog, Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228).
Here's a full list of resources regarding theApache Log4j vulnerability:
The Palo Alto Networks Full-Court Defense for Apache Log4j
Unit 42 Briefing: Apache Log4j Threat Update
Another Apache Log4j Vulnerability Is Actively Exploited in the Wild (CVE-2021-44228)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Subject | Likes |
---|---|
2 Likes | |
1 Like | |
1 Like | |
1 Like | |
1 Like |
User | Likes Count |
---|---|
3 | |
2 | |
2 | |
1 | |
1 |