Log4Shell: Critical Severity Apache Log4j Remote Code Execution Being Actively Exploited
ID: 493e53e8-203f-5aff-b255-67104d47336c
STIX ID: report--493e53e8-203f-5aff-b255-67104d47336c
Feed Name: Kudelski Security
Threat Score
Executive Summary: This advisory details the critical Log4j (Log4Shell) vulnerability enabling remote code execution via JNDI/LDAP lookups, describes incomplete fixes in 2.15.0 and subsequent patches (2.16.0/2.17.0), documents proof-of-concept exploit code and bypasses, reports active exploitation by nation-state and financially motivated actors (including ransomware deployments), and recommends urgent patching or removal of JndiLookup and other mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
