Tag: log4j

Here you will find all the articles with the tag: log4j.

UK NHS warns of Log4j vulnerability in VMware Horizon

UK NHS warns of Log4j vulnerability in VMware Horizon

The UK's National Health Service (NHS) has issued a warning stating that hackers are actively exploiting Log4j vulnerabilities in unpatched VMware Horizon servers. Log4j vulnerabilities are everything but a concern of the past. The problem continues to claim victims. The UK NHS recently issued a... Read more

date2 years ago
Security researchers find new Log4Shell in H2 database software

Security researchers find new Log4Shell in H2 database software

Security organization JFrog has found a vulnerability in H2. The problem is similar to Log4Shell, the infamous threat in Log4j. H2 consoles on servers accessible from the outside can be abused for remote code execution (RCE). Multiple lines of code in H2 send urls to a 'javax.naming.Context.look... Read more

date2 years ago
China-based Aquatic Panda hackers actively exploit Log4j

China-based Aquatic Panda hackers actively exploit Log4j

Aquatic Panda, a China-based hacking collective, directly exploited the Log4j vulnerability to attack an undisclosed academic institution. The attack was discovered and parried by CrowdStrike's Overwatch threat-hunting specialists. According to CrowdStrike, China-based hackers launched an attack... Read more

date2 years ago
Microsoft issues Defender updates to address Log4j vulnerability

Microsoft issues Defender updates to address Log4j vulnerability

Microsoft updated several Defender solutions to defend users against exploits of Log4j. Among other things, the updates allow companies to identify and resolve Log4j vulnerabilities faster. Specifically, Defender for Containers and Microsoft 365 Defender solutions underwent a change. Among other... Read more

date2 years ago
Apache releases new patch 2.17.1 for Log4j vulnerability

Apache releases new patch 2.17.1 for Log4j vulnerability

Another vulnerability was discovered in Log4j. Accordingly, the Apache Foundation released a patch. Version Log4j 2.17.1 fixes a newfound method for remote code execution. The vulnerability was found in version 2.17.0 and named CVE-2021-44832. Authorization to modify the configuration file allow... Read more

date2 years ago
The White House invests in open-source software security

The White House invests in open-source software security

The Biden administration is investing in open-source software security. Bloomberg reports that several open-source software providers and developers were invited to a governmental meeting in mid-January 2021. According to Bloomberg, U.S. National Security Advisor Jake Sullivan has invited key te... Read more

date2 years ago
1 2 3