Analyzing DNS logger logs, Viettel researchers conclude Log4Shell exploitation may have begun around September 4, 2021 - months before disclosure - hitting at least 10 organizations worldwide.
An overview of Log4Shell (CVE-2021-44228): unauthenticated JNDI injection RCE in Log4j 2.0-beta9 through 2.14.1, rated CVSS 10, noting JNDI injection research dates back to Black Hat 2016.
Bishop Fox's account of the first chaotic week of Log4shell (CVE-2021-44228): JNDI/LDAP payloads sprayed via HTTP headers and DNS exfiltration when outbound TCP was blocked.
Log4Shell (CVE-2021-44228) is a 10.0-critical RCE affecting Apache Log4j 2.0-beta9 to 2.14.1, hitting Apple, Cloudflare, Twitter, and Minecraft—considered worse than the 2017 Apache Struts flaw.
Find out if your organization is vulnerable to the Log4j vulnerabilities, read about the impact of CVE-2021-44228 and its variants, and learn mitigation steps to take.
Bishop Fox experts analyze CVE-2021-44228's impact: CVSS 10 unauthenticated RCE in Apache Log4j, first mass scanning on December 10, 2021, and affected projects from Elasticsearch to Struts.