RSS
Naked Security
Apache
Apache Commons Text
CVE-2022-42889
Log4J
Log4shell
string interpolation
Dangerous hole in Apache Commons Text – like Log4Shell all over again
CSRB
DHS
Security.txt
8 months on, US says Log4Shell will be around for “a decade or longer”
Threat Research
Crypto mining
Featured
Horizon
initial access broker
Security Operations
VMware
Horde of miner bots and backdoors leveraged Log4J to attack VMware Horizon servers
Exploit
vulnerability
Log4Shell: How the Attackers’ Faces Have Changed Over Time
MTR
Log4Shell: No Mass Abuse, But No Respite, What Happened?
CVE-2021-42392
H2
Java
JNDI
SQL
Log4Shell-like security hole found in popular Java SQL database engine H2
Apple
Instagram
S3 Ep64: Log4Shell again, scammers keeping busy, and Apple Home bug [Podcast + Transcript]
Equifax
ftc
patching
FTC threatens “legal action” over unpatched Log4j and other vulns
CVE-2021-44228
CVE-2021-44832
Patch
Log4Shell vulnerability Number Four: “Much ado about something”