AWS's Log4Shell Hot Patch Vulnerable to Container Escape and Privilege EscalationPalo Alto Unit 42·Jun 5, 22:41 UTC · Jun 5, 2024VulnerabilityCVE-2021-3100CVE-2021-3101CVE-2022-0070+2 CVEs47
Most attackers lose interest in Log4ShellThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Exploit / PoC in the wildCVE-2021-4422860
Log4Shell attacks expand to nation-state groups from China, Iran, North Korea, and TurkeyThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Threat actor in the wildCVE-2021-4422860
CISA tells federal agencies to patch Log4Shell before ChristmasThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2021-4422847
Threat actor target Ubiquiti network appliances using Log4Shell exploitsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Threat actor in the wild60
UK NHS: Threat actor targets VMware Horizon servers using Log4Shell exploitsThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Threat actor57
Night Sky ransomware operators exploit Log4Shell to target VMware Horizon serversSecurity Affairs·Jan 11, 14:52 UTC · Jan 11, 2022RansomwareCVE-2021-44228CVE-2021-26084CVE-2021-3447360
Answering Log4ShellKaspersky Securelist·Dec 21, 10:55 UTC · Dec 21, 2021Vulnerability in the wildCVE-2021-44228CVE-2021-45046CVE-2021-4510560
Conti ransomware gang exploits Log4Shell bug in its operationsSecurity Affairs·Dec 17, 21:44 UTC · Dec 17, 2021RansomwareCVE-2021-4422860
Conti ransomware group adopts Log4Shell exploitThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware57
Multiple Nation-State actors are exploiting Log4Shell flawSecurity Affairs·Dec 16, 12:24 UTC · Dec 16, 2021Threat actor in the wildCVE-2021-4422860
First Log4Shell attacks spreading ransomware have been spottedThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware57
FTC warns legal action against companies who fail to mitigate Log4ShellThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Policy & legal in the wild57
Attackers still exploit Log4Shell on VMware Horizon servers, CISA warnsHelp Net Security·Jun 24, 00:00 UTC · Jun 24, 2022Advisory in the wildCVE-2021-44228CVE-2022-2295460
Log4Shell exploitation: Which applications may be targeted next?Help Net Security·Apr 5, 00:00 UTC · Apr 5, 2022RansomwareCVE-2022-22965CVE-2021-44228160
TellYouThePass ransomware resurges and exploits Log4Shell flawSecurity Affairs·Dec 19, 14:08 UTC · Dec 19, 2021RansomwareCVE-2021-4422860
Microsoft: Nation-state Iranian hackers exploit Log4Shell against IsraelThe Record·Jan 11, 00:00 UTC · Jan 11, 2023Threat actor57
US: Iranian Hackers Breached Government with Log4ShellInfosecurity Magazine·Nov 17, 10:10 UTC · Nov 17, 2022Data breach57
Log4Shell Still Being Exploited to Hack VMWare Servers to Exfiltrate Sensitive DataThe Hacker News·Jun 24, 07:37 UTC · Jun 24, 2022VulnerabilityCVE-2021-44228CVE-2022-2295447
Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy RootkitThe Hacker News·Apr 2, 03:48 UTC · Apr 2, 2022Malware42
Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon ServersThe Hacker News·Jan 29, 06:06 UTC · Jan 29, 2022Ransomware in the wild60
Hackers exploit Log4Shell to drop Khonsari RansomwareSecurity Affairs·Dec 14, 20:57 UTC · Dec 14, 2021RansomwareCVE-2021-4422860
Quebec shuts down thousands of sites as disclosure of the Log4Shell flawSecurity Affairs·Dec 12, 20:27 UTC · Dec 12, 2021Exploit / PoCCVE-2021-4422860
Five Eyes issue joint advisory for defending against Log4ShellThe Record·Jan 4, 00:00 UTC · Jan 4, 2023Advisory42
Text4Shell, an RCE bug in Apache Commons Text librarySecurity Affairs·Oct 19, 22:51 UTC · Oct 19, 2022VulnerabilityCVE-2022-42889CVE-2021-4422847
Apache Commons Text flaw is not a repeat of Log4Shell (CVE-2022-42889)Help Net Security·Oct 19, 00:00 UTC · Oct 19, 2022Vulnerability in the wildCVE-2022-4288960
A new attack vector exploits the Log4Shell vulnerability on servers locallySecurity Affairs·Dec 20, 07:41 UTC · Dec 20, 2021Vulnerability in the wild57
Two Linux botnets already exploit Log4Shell flaw in Log4jSecurity Affairs·Dec 13, 07:36 UTC · Dec 13, 2021Malware42
Lazarus Group Targets Log4Shell Flaw Via Telegram BotsInfosecurity Magazine·Dec 11, 17:00 UTC · Dec 11, 2023Threat actorCVE-2021-4422860
Week in review: Log4Shell exploitation, DevSecOps myths, 56 vulnerabilities impacting OT devicesHelp Net Security·Jun 26, 00:00 UTC · Jun 26, 2022VulnerabilityCVE-2021-4422847
Log4Shell Used in a Third of Malware InfectionsInfosecurity Magazine·Mar 30, 09:47 UTC · Mar 30, 2022Malware42
China-linked APT Aquatic Panda leverages Log4Shell in recent attackSecurity Affairs·Dec 30, 05:36 UTC · Dec 30, 2021Vulnerability42
CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j VulnerabilitiesThe Hacker News·Dec 29, 03:34 UTC · Dec 29, 2021VulnerabilityCVE-2021-45046CVE-2021-45105CVE-2021-44228+2 CVEs47
Google: More than 35,000 Java packages impacted by Log4j vulnerabilitiesThe Record·Jan 18, 00:00 UTC · Jan 18, 2023VulnerabilityCVE-2021-44228CVE-2021-4504647
UK's NHS Digital warns of an RCE in Okta Advanced Server Access clientSecurity Affairs·Feb 26, 10:45 UTC · Feb 26, 2022VulnerabilityCVE-2022-24295CVE-2021-45105CVE-2021-45046+1 CVEs47
Pay attention to Log4j attacks, Dutch National Cybersecurity Centre warnsSecurity Affairs·Jan 22, 20:34 UTC · Jan 22, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-4104+1 CVEs60
The Log4j saga: New vulnerabilities and attack vectors discoveredHelp Net Security·Dec 20, 00:00 UTC · Dec 20, 2021VulnerabilityCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs47
North Korean hackers using Log4J vulnerability in global campaignThe Record·Dec 11, 20:36 UTC · Dec 11, 2023VulnerabilityCVE-2021-4422847
Quarterly Report: Incident Response Trends in Q2 2022Cisco Talos·Jul 26, 14:03 UTC · Jul 26, 2022RansomwareCVE-2021-44228CVE-2021-4504660
While attackers begin exploiting a second Log4j flaw, a third one emergesSecurity Affairs·Dec 18, 14:00 UTC · Dec 18, 2021RansomwareCVE-2021-45046CVE-2021-4422860