Log4Shell attacks are spreading fast after flaw exploited
Log4Shell attacks are spreading fast after flaw exploited Apache says a patch is available, so update now When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works. Days after the dangerous Log4Shell zero-day vulnerability was found in the Apache Log4j Java-based logging platform, experts have begun warning that malicious actors are already exploiting the flaw against vulnerableendpointsin various ways. Microsofthas published a list of ways Log4Shell (tracked as CVE-2021-44228) is being used: to install malware, cryptominers, to add the devices to the Mirai and Muhstik botnets, to drop Cobalt Strike beacons, to scan for information disclosure, or for lateral movement throughout the affected network....