Log4Shell Vulnerability Actively Used to Inject Malware into VMWare Horizon Servers
Summary
The aftershocks of the earthquake caused in the IT security sector by the Log4Shell or Log4j vulnerability that was unearthed in late 2021 are still making waves. Security researchers discovered ongoing attacks targeting VMWare Horizon servers and infecting them with different malware, abusing the infamous vulnerability. Log4Shell, dubbed by security experts the "vulnerability of the decade", received a perfect severity score of 10.0 when it was cataloged. Once the systems have been compromised using Log4Shell, the hackers install legitimate remote access and viewing tools that are used as backdoors. Attackers dont even have to try particularly hard, because due to the huge number of systems running the underlying software used in the exploits, there will likely be unpatched instances for years to come, just like researchers predicted.