Weekly Roundup: What We’ve Learned About the Log4j Vulnerability
ID: 1f5a5762-2708-508f-8930-d50323099175
STIX ID: report--1f5a5762-2708-508f-8930-d50323099175
Feed Name: Zscaler Security Research Blog
Threat Score
**Log4Shell (CVE-2021-44228) summary:** Apache Log4j's remote code execution flaw (CVSS 10.0) is widely present across applications and cloud services and is being actively exploited in the wild—scanners, botnets (Mirai, Kinsing), Cobalt Strike, cryptomining, and new ransomware families have been observed—so organizations should prioritize patching/mitigations, attack surface discovery, and strengthen defenses with zero trust, deception, and segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
