AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege EscalationPalo Alto Unit 42·Jun 5, 22:41 UTC · Jun 5, 2024VulnerabilityCVE-2021-3100CVE-2021-3101CVE-2022-0070+2 CVEs47
CISA tells federal agencies to patch Log4Shell before ChristmasThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2021-4422847
Answering Log4ShellKaspersky Securelist·Dec 21, 10:55 UTC · Dec 21, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-45046CVE-2021-4510560
Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive DataThe Hacker News·Jun 24, 07:37 UTC · Jun 24, 2022VulnerabilityCVE-2021-44228CVE-2022-2295447
Text4Shell, an RCE bug in Apache Commons Text librarySecurity Affairs·Oct 19, 22:51 UTC · Oct 19, 2022VulnerabilityCVE-2022-42889CVE-2021-4422847
Apache Commons Text flaw is not a repeat of Log4Shell (CVE-2022-42889)Help Net Security·Oct 19, 00:00 UTC · Oct 19, 2022Vulnerability in the wildCVE-2022-4288960
A new attack vector exploits the Log4Shell vulnerability on servers locallySecurity Affairs·Dec 20, 07:41 UTC · Dec 20, 2021Vulnerability in the wild57
Week in review: Log4Shell exploitation, DevSecOps myths, 56 vulnerabilities impacting OT devicesHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2022VulnerabilityCVE-2021-4422847
China-linked APT Aquatic Panda leverages Log4Shell in recent attackSecurity Affairs·Dec 30, 05:36 UTC · Dec 30, 2021Vulnerability42
CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j VulnerabilitiesThe Hacker News·Dec 29, 03:34 UTC · Dec 29, 2021VulnerabilityCVE-2021-45046CVE-2021-45105CVE-2021-44228+2 CVEs47
Google: More than 35,000 Java packages impacted by Log4j vulnerabilitiesThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2021-44228CVE-2021-4504647
UK's NHS Digital warns of an RCE in Okta Advanced Server Access clientSecurity Affairs·Feb 26, 10:45 UTC · Feb 26, 2022VulnerabilityCVE-2022-24295CVE-2021-45105CVE-2021-45046+1 CVEs47
The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2021VulnerabilityCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs47
North Korean hackers using Log4J vulnerability in global campaignThe Record·Dec 11, 20:36 UTC · Dec 11, 2023VulnerabilityCVE-2021-4422847
New Log4j Patch Released to Fix DoS FlawInfosecurity Magazine·Dec 20, 10:43 UTC · Dec 20, 2021VulnerabilityCVE-2021-4422847
New Local Attack Vector Expands the Attack Surface of Log4j VulnerabilityThe Hacker News·Dec 20, 05:03 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-44228+1 CVEs60
Iran-linked TunnelVision APT is actively exploiting the Log4j vulnerabilitySecurity Affairs·Feb 18, 15:21 UTC · Feb 18, 2022VulnerabilityCVE-2018-1337947
Microsoft Warns of Continued Attacks Exploiting Apache Log4j VulnerabilitiesThe Hacker News·Jan 5, 05:13 UTC · Jan 5, 2022Vulnerability in the wildCVE-2021-45046CVE-2021-45105CVE-2021-4104+1 CVEs60
Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw EmergesThe Hacker News·Dec 17, 05:54 UTC · Dec 17, 2021VulnerabilityCVE-2021-45046CVE-2021-4422847
What Changes When Your Software Supply Chain Includes AI Writing Your Code?The Hacker News·Jul 7, 11:30 UTC · Jul 7, 2026Vulnerability42
32% Of Top-Exploited Vulnerabilities Are Over A Decade OldHelp Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Vulnerability in the wild157
Skyhawk Security enhances Autonomous Purple Team to secure cloud appsHelp Net Security·May 5, 20:47 UTC · May 5, 2025Vulnerability42
RedTail Crypto-Mining Malware Exploiting Palo Alto Networks Firewall VulnerabilityThe Hacker News·May 31, 04:58 UTC · May 31, 2024VulnerabilityCVE-2024-3400CVE-2023-1389CVE-2018-20062+6 CVEs47
Top 12 vulnerabilities routinely exploited in 2022Help Net Security·Aug 7, 07:41 UTC · Aug 7, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+23 CVEs47
Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities DetectedThe Hacker News·May 3, 04:08 UTC · May 3, 2023Vulnerability in the wildCVE-2023-1389CVE-2021-45046CVE-2023-21839+1 CVEs60
The potential pitfalls of open source managementHelp Net Security·Feb 23, 00:00 UTC · Feb 23, 2023Vulnerability42
Suspected Iranian APT accessed federal server via Log4j vulnerabilityThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Vulnerability42
Experts warn of CVE-2022Security Affairs·Oct 21, 20:51 UTC · Oct 21, 2022Vulnerability in the wildCVE-2022-42889160
Google Launches GUAC Open Source Project to Secure Software Supply ChainThe Hacker News·Oct 20, 17:09 UTC · Oct 20, 2022Vulnerability42
1,859 Android and iOS apps contain hardSecurity Affairs·Sep 1, 14:01 UTC · Sep 1, 2022Vulnerability42
Google bug bounty program now covers Open Source projectsSecurity Affairs·Aug 30, 16:51 UTC · Aug 30, 2022Vulnerability42
Google Launches Major Open Source Bug Bounty ProgramInfosecurity Magazine·Aug 30, 12:00 UTC · Aug 30, 2022Vulnerability42
Scribe Integrity helps developers authenticate open-source and proprietary source codeHelp Net Security·Jul 14, 00:00 UTC · Jul 14, 2022Vulnerability42
EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS VulnerabilitiesThe Hacker News·May 31, 04:11 UTC · May 31, 2022VulnerabilityCVE-2022-22954CVE-2022-1388CVE-2022-22947+5 CVEs47
Tidelift raises $27 million to improve open source software supply chain securityHelp Net Security·May 25, 00:00 UTC · May 25, 2022Vulnerability42
U.S. Cybersecurity Agency Lists 2021's Top 15 Most Exploited Software VulnerabilitiesThe Hacker News·May 9, 02:55 UTC · May 9, 2022VulnerabilityCVE-2020-0688CVE-2019-11510CVE-2018-1337947
Steady rise in severe web vulnerabilitiesHelp Net Security·Apr 8, 00:00 UTC · Apr 8, 2022Vulnerability42
Alibaba Suffers Government Crackdown Over Log4jInfosecurity Magazine·Dec 23, 10:05 UTC · Dec 23, 2021Vulnerability42
Apache Issues 3rd Patch to Fix New HighThe Hacker News·Dec 20, 05:02 UTC · Dec 20, 2021Vulnerability in the wildCVE-2021-45105CVE-2021-45046CVE-2021-4422860