Six Months Later: Assessing the OT and ICS Risks of the Log4j Vulnerability
ID: f3990617-90f9-531c-b6b3-77eed3ac330e
STIX ID: report--f3990617-90f9-531c-b6b3-77eed3ac330e
Feed Name: Dragos Blog
The report assesses the continued and widespread risk posed by the Log4j (CVE-2021-44228) vulnerability, noting that many Java-based systems—including ICS/OT products—remain unpatched and exposed; it cites large-scale measurements (thousands of vulnerable packages, tens of thousands of internet-facing vulnerable applications), documents active exploitation and compromises (e.g., VMware View, PingFederate SSO), and attributes attacks to state-sponsored groups such as Stonefly, APT35, and APT41 while warning that attackers may pivot from enterprise to OT networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
