It could take years for applications using vulnerable version of Java log4j library to be patched, says expert
IT admins urged to take vulnerability seriously as vendors rush to issue patches or mitigations
Stay updated with breaking news from Apache Struts. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
IT admins urged to take vulnerability seriously as vendors rush to issue patches or mitigations
Researchers have already seen examples of threat actors planting Cobalt Strike beacons and cryptomining apps after successfully exploiting the bug
A high-severity flaw in Apache Log4j has set off a storm of cyberattacks - and some unusual defensive tactics by security vendors.
Log4Shell update: CVE-2021-44228 affects only versions 2.x of Apache Log4j (i.e., Apache Log4j 2), according to security researchers.
Businesses around the world will spend years dealing with the repercussions from critical vulnerabilities discovered in Apache log4j, Tenable co-founder...