logo

Six Months Later: Assessing the OT and ICS Risks of the Log4j Vulnerability

ID: f3990617-90f9-531c-b6b3-77eed3ac330e

STIX ID: report--f3990617-90f9-531c-b6b3-77eed3ac330e

Feed Name: Dragos Blog

Threat Score
90/100

Date Published: 2021-07-21

Date Updated: 2026-04-27

...
...

The report assesses the continued and widespread risk posed by the Log4j (CVE-2021-44228) vulnerability, noting that many Java-based systems—including ICS/OT products—remain unpatched and exposed; it cites large-scale measurements (thousands of vulnerable packages, tens of thousands of internet-facing vulnerable applications), documents active exploitation and compromises (e.g., VMware View, PingFederate SSO), and attributes attacks to state-sponsored groups such as Stonefly, APT35, and APT41 while warning that attackers may pivot from enterprise to OT networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.