Cloudflare and Cisco Talos say Log4j zero-day attacks were first observed on December 1 and 2, ahead of mass exploitation over the weekend
While a public proof-of-concept code was released last Thursday, attacks exploiting the Log4Shell vulnerability started two weeks ago.
Context & Ripple Effects
Cloudflare and Cisco Talos place exploitation before the public proof-of-concept and before coverage documented waves of attacks against unpatched Apache servers. That earlier start explains why the incident rapidly became a broad exposure-management problem rather than a patching event alone.
The subsequent surge to more than 800,000 attacks within 72 hours makes the initial observations consequential: defenders had to account for activity that may have occurred before the vulnerability was widely known.
First-order effects
- Organizations assessing Log4Shell exposure need to extend log review and compromise hunting back to December 1, rather than treating the public proof-of-concept as the start of attacker activity.
Second-order effects
- Incident-response teams must separate patch deployment from compromise remediation, since the related attack waves included data theft, botnets and cryptomining on systems that had remained unpatched.
Third-order effects
- The episode supports a security-operations model that assumes serious flaws may be exploited before public disclosure and retains telemetry for retrospective investigation; later warnings of Log4Shell exploitation in the wild show why the response horizon extends beyond the initial patch cycle.
The trend: High-severity open-source vulnerabilities are increasingly managed as pre-disclosure intrusion risks with long-lived exploitation tails, not one-time patch emergencies.