Log4j Exploits Diversify To Expose Popular App & Service Vulnerabilities, Issue Likely to Linger
Summary
Just when you thought 2021 had already been bad enough for cyber security, with all the high-profile ransomware attacks and massive data leaks that took place over the past twelve months, the Log4j exploit came along and trumped everything else. The latest reports from security outlets indicate that the alternative ways to exploit the vulnerability are growing and mutating, and it is also likely that this issue will haunt us for a while. The Log4j vulnerability, given the name LogShell, logged as CVE-2021-44228 and bearing a maximum severity score of 10, was first spotted by Alibaba in late November 2021 and has been exploited heavily ever since. According to security researchers with Check Point, within the span of mere days threat actors have already come up with a staggering 60+ variations and alterations of the initial exploit. The incredible surface area offered by the exploit also means that even as patches are rolled out and applied globally, there will still be vulnerable systems for months to come.